VYPR

CVEs

38,030 total · page 211 of 761

  • CVE-2025-50251CriAug 13, 2025
    risk 0.59cvss 9.1epss 0.00

    Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.

  • CVE-2025-54382CriAug 13, 2025
    risk 0.63cvss 9.6epss 0.07

    Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (RCE) vulnerability exists in the Cherry Studio platform when connecting to streamableHttp MCP servers. The issue arises from the server’s implicit trust in…

  • CVE-2025-54074CriAug 13, 2025
    risk 0.00cvss 9.8epss 0.02

    Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.2.5 to 1.5.1, Cherry Studio is vulnerable to OS Command Injection during a connection with a malicious MCP server in HTTP Streamable mode. Attackers can setup a malicious MCP server with…

  • CVE-2025-8913CriAug 13, 2025
    risk 0.64cvss 9.8epss 0.01

    Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.

  • CVE-2025-8760CriAug 13, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the component fcgi_server. The manipulation of the argument Authorization leads to buffer overflow. It is possible to initiate the attack remotely.

  • CVE-2025-6715CriAug 13, 2025
    risk 0.64cvss 9.8epss 0.01

    The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

  • CVE-2025-7384CriAug 13, 2025
    risk 0.64cvss 9.8epss 0.01

    The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization of untrusted input in the get_lead_detail function. This makes it possible for unauthenticated…

  • CVE-2025-49457CriAug 12, 2025
    risk 0.62cvss 9.6epss 0.01

    Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access

  • CVE-2025-55168CriAug 12, 2025
    risk 0.00cvss 9.8epss 0.00

    WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a SQL Injection vulnerability was identified in the /html/saude/aplicar_medicamento.php endpoint, specifically in the id_fichamedica parameter. This…

  • CVE-2025-25256CriAug 12, 2025
    risk 0.69cvss 9.8epss 0.65

    An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, FortiSIEM 7.0.0 through 7.0.3, FortiSIEM…

  • CVE-2025-53766CriAug 12, 2025
    risk 0.64cvss 9.8epss 0.08

    Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

  • CVE-2025-50171CriAug 12, 2025
    risk 0.59cvss 9.1epss 0.01

    Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-50165CriAug 12, 2025
    risk 0.64cvss 9.8epss 0.10

    Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

  • CVE-2025-55167CriAug 12, 2025
    risk 0.00cvss 9.8epss 0.01

    WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a SQL Injection vulnerability was identified in the /html/funcionario/dependente_remover.php endpoint, specifically in the id_dependente parameter.…

  • CVE-2025-55010CriAug 12, 2025
    risk 0.00cvss 9.1epss 0.01

    Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization vulnerability in the ProjectEventActvityFormatter allows admin users the ability to instantiate arbitrary php objects by modifying the event["data"]…

  • CVE-2025-40746CriAug 12, 2025
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not properly validate input for a backup script. This could allow an authenticated remote attacker with high privileges in the application to execute arbitrary code…

  • CVE-2025-8059CriAug 12, 2025
    risk 0.57cvss 9.8epss 0.00

    The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input validation within the rgfr_registration() function in all versions up to, and including, 2.0.6. This makes it possible for unauthenticated attackers to create…

  • CVE-2025-42957CriAug 12, 2025
    risk 0.64cvss 9.9epss 0.02

    SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a…

  • CVE-2025-42950CriAug 12, 2025
    risk 0.64cvss 9.9epss 0.01

    SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability…

  • CVE-2024-32640CriAug 11, 2025
    risk 0.62cvss 9.8epss 0.77

    MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7…

  • CVE-2025-53187CriAug 11, 2025
    risk 0.64cvss 9.8epss 0.01

    Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to bypass authentication. This vulnerability may allow an attacker to change the system time, access files, and make function…

  • CVE-2025-45146CriAug 11, 2025
    risk 0.64cvss 9.8epss 0.01

    ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code via supplying crafted data.

  • CVE-2012-10040CriAug 11, 2025
    risk 0.64cvss —epss 0.03

    Openfiler v2.x contains a command injection vulnerability in the system.html page. The device parameter is used to instantiate a NetworkCard object, whose constructor in network.inc calls exec() with unsanitized input. An authenticated attacker can exploit this to execute…

  • CVE-2012-10039CriAug 11, 2025
    risk 0.64cvss —epss 0.03

    ZEN Load Balancer versions 2.0 and 3.0-rc1 contain a command injection vulnerability in content2-2.cgi. The filelog parameter is passed directly into a backtick-delimited exec() call without sanitation. An authenticated attacker can inject arbitrary shell commands, resulting in…

  • CVE-2012-10038CriAug 11, 2025
    risk 0.64cvss —epss 0.02

    Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in upload_banners.php. The banner upload feature fails to validate file types or enforce authentication, allowing remote attackers to upload malicious PHP files. These files are stored in a…

  • CVE-2012-10037CriAug 11, 2025
    risk 0.64cvss —epss 0.02

    PhpTax version 0.8 contains a remote code execution vulnerability in drawimage.php. The pfilez GET parameter is unsafely passed to the exec() function without sanitization. A remote attacker can inject arbitrary shell commands, leading to code execution under the web server's…

  • CVE-2025-8853CriAug 11, 2025
    risk 0.64cvss 9.8epss 0.01

    Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.

  • CVE-2025-8660CriAug 11, 2025
    risk 0.64cvss 9.8epss 0.00

    Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed.

  • CVE-2025-8854CriAug 11, 2025
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow in LoadOFF in bulletphysics bullet3 before 3.26 on all platforms allows remote attackers to execute arbitrary code via a crafted OFF file with an overlong initial token processed by the VHACD test utility or invoked indirectly through PyBullet's vhacd…

  • CVE-2025-54997CriAug 9, 2025
    risk 0.52cvss 9.1epss 0.00

    OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, some OpenBao deployments intentionally limit privileged API operators from executing system code or making…

  • CVE-2025-6573CriAug 9, 2025
    risk 0.64cvss 9.8epss 0.00

    Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from the trusted execution environment (TEE).

  • CVE-2012-10053CriAug 8, 2025
    risk 0.64cvss —epss 0.02

    Simple Web Server 2.2 rc2 contains a stack-based buffer overflow vulnerability in its handling of the Connection HTTP header. When a remote attacker sends an overly long string in this header, the server uses vsprintf() without proper bounds checking, leading to a buffer…

  • CVE-2012-10052CriAug 8, 2025
    risk 0.64cvss —epss 0.02

    EGallery version 1.2 contains an unauthenticated arbitrary file upload vulnerability in the uploadify.php script. The application fails to validate file types or enforce authentication, allowing remote attackers to upload malicious PHP files directly into the web-accessible…

  • CVE-2012-10050CriAug 8, 2025
    risk 0.64cvss —epss 0.02

    CuteFlow version 2.11.2 and earlier contains an arbitrary file upload vulnerability in the restart_circulation_values_write.php script. The application fails to validate or restrict uploaded file types, allowing unauthenticated attackers to upload arbitrary PHP files to the…

  • CVE-2012-10049CriAug 8, 2025
    risk 0.64cvss —epss 0.02

    WebPageTest version 2.6 and earlier contains an arbitrary file upload vulnerability in the resultimage.php script. The application fails to validate or sanitize user-supplied input before saving uploaded files to a publicly accessible directory. This flaw allows remote attackers…

  • CVE-2012-10047CriAug 8, 2025
    risk 0.68cvss —epss 0.01

    Cyclope Employee Surveillance Solution versions 6.x are vulnerable to a SQL injection flaw in its login mechanism. The username parameter in the auth-login POST request is not properly sanitized, allowing attackers to inject arbitrary SQL statements. This can be leveraged to…

  • CVE-2012-10046CriAug 8, 2025
    risk 0.64cvss —epss 0.04

    The E-Mail Security Virtual Appliance (ESVA) (tested on version ESVA_2057) contains an unauthenticated command injection vulnerability in the learn-msg.cgi script. The CGI handler fails to sanitize user-supplied input passed via the id parameter, allowing attackers to inject…

  • CVE-2012-10045CriAug 8, 2025
    risk 0.64cvss —epss 0.02

    XODA version 0.4.5 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary PHP code on the server. The flaw resides in the upload functionality, which fails to properly validate or restrict uploaded file types. By crafting a…

  • CVE-2012-10044CriAug 8, 2025
    risk 0.68cvss —epss 0.02

    MobileCartly version 1.0 contains an arbitrary file creation vulnerability in the savepage.php script. The application fails to perform authentication or authorization checks before invoking file_put_contents() on attacker-controlled input. An unauthenticated attacker can…

  • CVE-2012-10043CriAug 8, 2025
    risk 0.63cvss —epss 0.00

    A stack-based buffer overflow vulnerability exists in ActFax Server version 4.32, specifically in the "Import Users from File" functionality of the client interface. The application fails to properly validate the length of tab-delimited fields in .exp files, leading to unsafe…

  • CVE-2012-10041CriAug 8, 2025
    risk 0.64cvss —epss 0.04

    WAN Emulator v2.3 contains two unauthenticated command execution vulnerabilities. The result.php script calls shell_exec() with unsanitized input from the pc POST parameter, allowing remote attackers to execute arbitrary commands as the www-data user. The system also includes a…

  • CVE-2012-10036CriAug 8, 2025
    risk 0.64cvss —epss 0.02

    Project Pier 0.8.8 and earlier contains an unauthenticated arbitrary file upload vulnerability in tools/upload_file.php. The upload handler fails to validate the file type or enforce authentication, allowing remote attackers to upload malicious PHP files directly into a…

  • CVE-2010-10013CriAug 8, 2025
    risk 0.64cvss —epss 0.02

    An unauthenticated remote command execution vulnerability exists in AjaXplorer (now known as Pydio Cells) versions prior to 2.6. The flaw resides in the checkInstall.php script within the access.ssh plugin, which fails to properly sanitize user-supplied input to the destServer…

  • CVE-2025-5095CriAug 8, 2025
    risk 0.64cvss 9.8epss 0.01

    Burk Technology ARC Solo's password change mechanism can be utilized without proper authentication procedures, allowing an attacker to take over the device. A password change request can be sent directly to the device's HTTP endpoint without providing valid credentials. The…

  • CVE-2025-52913CriAug 8, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allow an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. A successful exploit could allow unauthorized access,…

  • CVE-2025-8284CriAug 8, 2025
    risk 0.64cvss 9.8epss 0.01

    By default, the Packet Power Monitoring and Control Web Interface do not enforce authentication mechanisms. This vulnerability could allow unauthorized users to access and manipulate monitoring and control functions.

  • CVE-2025-8731CriAug 8, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown part of the component SSH Service. The manipulation leads to use of default credentials. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2025-8356CriAug 8, 2025
    risk 0.65cvss 9.8epss 0.19

    In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system.

  • CVE-2025-8730CriAug 8, 2025
    risk 0.67cvss 9.8epss 0.03

    A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functionality of the component Web Interface. The manipulation leads to hard-coded credentials. The attack may be launched remotely. The…

  • CVE-2025-53606CriAug 8, 2025
    risk 0.57cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recommended to upgrade to version 2.5.0, which fixes the issue.