VYPR

CVEs

31,861 total · page 211 of 638

  • CVE-2025-14566HigDec 12, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The impacted element is an unknown function of the file /Profilers/SProfile/reg.php. Performing a manipulation of the argument USN results in sql injection. It is…

  • CVE-2025-14565HigDec 12, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affected element is an unknown function of the file /Profilers/SProfile/login1.php. Such manipulation of the argument Username leads to sql injection. The attack…

  • CVE-2025-36745HigDec 12, 2025
    risk 0.51cvss 7.8epss 0.00

    SolarEdge SE3680H  ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attacker with network or local access can exploit these flaws to achieve remote code execution, privilege escalation, or disclosure of sensitive information.

  • CVE-2025-13506HigDec 12, 2025
    risk 0.57cvss 8.8epss 0.00

    Execution with Unnecessary Privileges vulnerability in Nebim Neyir Computer Industry and Services Inc. Nebim V3 ERP allows Expanding Control over the Operating System from the Database. This issue affects Nebim V3 ERP: from 2.0.59 before 3.0.1.

  • CVE-2025-12835HigDec 12, 2025
    risk 0.47cvss 7.3epss 0.00

    The WooMulti WordPress plugin through 17 does not validate a file parameter when deleting files, which could allow any authenticated users, such as subscriber to delete arbitrary files on the server.

  • CVE-2025-14169HigDec 12, 2025
    risk 0.49cvss 7.5epss 0.00

    The FunnelKit - Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'opid' parameter in all versions up to, and including, 3.13.1.5 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2025-14068HigDec 12, 2025
    risk 0.49cvss 7.5epss 0.00

    The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions up to, and including, 0.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

  • CVE-2025-12570HigDec 12, 2025
    risk 0.47cvss 7.2epss 0.00

    The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping in the data-to-image.php and pdf-to-image.php files. This…

  • CVE-2025-14044HigDec 12, 2025
    risk 0.53cvss 8.1epss 0.00

    The Visitor Logic Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.3 via deserialization of untrusted input from the `lpblocks` cookie. This is due to the `lp_track()` function passing unsanitized cookie data directly to…

  • CVE-2025-13334HigDec 12, 2025
    risk 0.53cvss 8.1epss 0.00

    The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a missing capability check on the "blaze_demo_importer_install_demo" function in all versions up to, and including, 1.0.13. This makes it possible for…

  • CVE-2025-12968HigDec 12, 2025
    risk 0.57cvss 8.8epss 0.01

    The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in all versions up to, and including, 2.14.42. This is due to the `upload_file` function in the `infility_import_file` class only validating…

  • CVE-2025-12824HigDec 12, 2025
    risk 0.57cvss 8.8epss 0.01

    The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.2 via the 'player_leaderboard' shortcode. This is due to the plugin using an unsanitized user-supplied value from the shortcode's 'mode' attribute in a…

  • CVE-2025-13886HigDec 12, 2025
    risk 0.49cvss 7.5epss 0.01

    The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1 via the 'template' parameter in the `book` shortcode due to insufficient path sanitization. This makes it possible for authenticated attackers, with…

  • CVE-2025-10451HigDec 12, 2025
    risk 0.53cvss 8.2epss 0.00

    Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption.

  • CVE-2024-58310HigDec 11, 2025
    risk 0.57cvss epss 0.01

    APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit directory traversal techniques to read critical system files like /etc/passwd by…

  • CVE-2024-58306HigDec 11, 2025
    risk 0.57cvss epss 0.00

    minaliC 2.0.0 contains a denial of service vulnerability that allows remote attackers to crash the web server by sending oversized GET requests. Attackers can send crafted HTTP requests with excessive data to overwhelm the server and cause service interruption.

  • CVE-2024-58304HigDec 11, 2025
    risk 0.49cvss 7.5epss 0.00

    SPA-CART CMS 1.9.0.3 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr' parameter in the product edit form to…

  • CVE-2024-58303HigDec 11, 2025
    risk 0.56cvss epss 0.01

    FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject malicious code into email templates. Attackers can execute system commands by inserting crafted template expressions that trigger arbitrary code execution…

  • CVE-2024-58300HigDec 11, 2025
    risk 0.57cvss epss 0.00

    Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attackers to retrieve randomly generated credentials via a network request. Attackers can send a specific hex-encoded command to port 12777 to obtain username and…

  • CVE-2024-58295HigDec 11, 2025
    risk 0.56cvss epss 0.00

    ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the theme installation process. Attackers can upload a ZIP archive with a PHP file containing system commands, which can then be…

  • CVE-2024-58293HigDec 11, 2025
    risk 0.56cvss epss 0.00

    Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to execute template expressions in multiple form input fields. Attackers can inject template payloads in items, taxes, transactions, and vendor name fields to perform…

  • CVE-2024-58288HigDec 11, 2025
    risk 0.57cvss epss 0.00

    Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service configuration. Attackers can exploit the unquoted binary path to execute arbitrary code with elevated LocalSystem privileges by placing malicious executables…

  • CVE-2025-66590HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write vulnerability can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to arbitrary code execution or a system crash.

  • CVE-2025-66588HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    In AzeoTech DAQFactory release 20.7 (Build 2555), an access of uninitialized pointer vulnerability can be exploited by an attacker which can lead to arbitrary code execution.

  • CVE-2025-66586HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current…

  • CVE-2025-66585HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current process.

  • CVE-2025-14537HigDec 11, 2025
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in code-projects Class and Exam Timetable Management 1.0. Affected by this issue is some unknown functionality of the file /preview7.php. This manipulation of the argument course_year_section/semester causes sql injection. Remote exploitation of…

  • CVE-2025-14536HigDec 11, 2025
    risk 0.47cvss 7.3epss 0.01

    A security flaw has been discovered in code-projects Class and Exam Timetable Management 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument username/password results in sql injection.…

  • CVE-2025-14529HigDec 11, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The affected element is an unknown function of the file /admin/admin_running.php. This manipulation of the argument pid causes sql injection. It is possible to initiate the attack remotely. The exploit…

  • CVE-2025-14527HigDec 11, 2025
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unknown code of the file /view_book.php. Executing a manipulation of the argument book_id can lead to sql injection. The attack can be executed remotely. The…

  • CVE-2025-13124HigDec 11, 2025
    risk 0.49cvss 7.6epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Netiket Information Technologies Ltd. Co. ApplyLogic allows Exploitation of Trusted Identifiers. This issue affects ApplyLogic: through 01.12.2025.

  • CVE-2025-14523HigDec 11, 2025
    risk 0.53cvss 8.2epss 0.01

    A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to…

  • CVE-2025-14515HigDec 11, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_unit.php. Such manipulation of the argument txtunitDetails leads to sql injection. The attack can be launched remotely.…

  • CVE-2025-13003HigDec 11, 2025
    risk 0.49cvss 7.6epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Aksis Computer Services and Consulting Inc. AxOnboard allows Exploitation of Trusted Identifiers. This issue affects AxOnboard: from 3.2.0 before 3.3.0.

  • CVE-2025-14514HigDec 11, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/add_distributor.php. This manipulation of the argument txtDistributorAddress causes sql injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2025-64701HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user who can log in to a Windows system with the affected product to gain administrator privileges. As a result, sensitive information may be accessed or altered,…

  • CVE-2025-67738HigDec 11, 2025
    risk 0.55cvss 8.5epss 0.00

    squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions (the "cms"…

  • CVE-2025-67719HigDec 11, 2025
    risk 0.48cvss epss 0.00

    Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0.0-beta1 through 5.0.3 do not have password validation. During the transition from v4 to v5 an error was introduced into validation code which causes the validation of the previous password not to…

  • CVE-2025-67718HigDec 11, 2025
    risk 0.50cvss epss 0.00

    Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through 4.4.2 contain a flaw in path handling which could allow an attacker to access protected API endpoints by sending a crafted request path. An unauthenticated or…

  • CVE-2025-13155HigDec 10, 2025
    risk 0.51cvss 7.8epss 0.00

    An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user to execute code with elevated privileges.

  • CVE-2025-13152HigDec 10, 2025
    risk 0.51cvss 7.8epss 0.00

    A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.

  • CVE-2025-12046HigDec 10, 2025
    risk 0.51cvss 7.8epss 0.00

    A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to execute code with elevated privileges under certain conditions.

  • CVE-2024-2104HigDec 10, 2025
    risk 0.57cvss 8.8epss 0.00

    Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read and write device control commands through the mobile app service wich could render the device unusable.

  • CVE-2025-41358HigDec 10, 2025
    risk 0.54cvss epss 0.00

    Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in…

  • CVE-2025-7073HigDec 10, 2025
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback)…

  • CVE-2025-14390HigDec 10, 2025
    risk 0.57cvss 8.8epss 0.00

    The Video Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in version <= 5.0.4. This is due to missing or incorrect nonce validation on the video_merchant_add_video_file() function. This makes it possible for unauthenticated attackers to upload arbitrary…

  • CVE-2025-1161HigDec 10, 2025
    risk 0.46cvss 7.1epss 0.00

    Incorrect Use of Privileged APIs vulnerability in NomySoft Information Technology Training and Consulting Inc. Nomysem allows Privilege Escalation. This issue affects Nomysem: through May 2025.

  • CVE-2025-12952HigDec 10, 2025
    risk 0.57cvss epss 0.00

    A privilege escalation vulnerability exists in Google Cloud's Dialogflow CX. Dialogflow agent developers with Webhook editor permission are able to configure Webhooks using Dialogflow service agent access token authentication. This allows the attacker to escalate their…

  • CVE-2025-9571HigDec 10, 2025
    risk 0.57cvss epss 0.00

    A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifacts to a Data Fusion instance can execute arbitrary code within the core AppFabric component. This could allow the attacker to gain control over the Data…

  • CVE-2025-13073HigDec 10, 2025
    risk 0.46cvss 7.1epss 0.00

    The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin