VYPR

CVEs

38,036 total · page 223 of 761

  • CVE-2025-28970CriJun 27, 2025
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in pep.vn WP Optimize By xTraffic wp-optimize-by-xtraffic allows Object Injection.This issue affects WP Optimize By xTraffic: from n/a through <= 5.1.6.

  • CVE-2025-23967CriJun 27, 2025
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpopal GG Bought Together for WooCommerce gg-bought-together allows SQL Injection.This issue affects GG Bought Together for WooCommerce: from n/a through <= 1.0.2.

  • CVE-2024-12827CriJun 27, 2025
    risk 0.64cvss 9.8epss 0.00

    The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.6. This is due to the plugin not properly checking for an empty token value prior to resetting a user's password…

  • CVE-2025-6688CriJun 27, 2025
    risk 0.57cvss 9.8epss 0.01

    The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due to the plugin not properly verifying a user's identity prior to logging them in through the create_user() function. This makes it possible for unauthenticated…

  • CVE-2025-5306CriJun 27, 2025
    risk 0.68cvss 9.8epss 0.36

    Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778

  • CVE-2025-3699CriJun 26, 2025
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W all versions, G-50A all versions, GB-50 all versions, GB-50A all versions, GB-24A all versions, G-150AD all versions, AG-150A-A all versions, AG-150A-J all…

  • CVE-2015-0843CriJun 26, 2025
    risk 0.64cvss 9.8epss 0.00

    yubiserver before 0.6 is prone to buffer overflows due to misuse of sprintf.

  • CVE-2015-0842CriJun 26, 2025
    risk 0.64cvss 9.8epss 0.00

    yubiserver before 0.6 is prone to SQL injection issues, potentially leading to an authentication bypass.

  • CVE-2014-7210CriJun 26, 2025
    risk 0.64cvss 9.8epss 0.00

    pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends are not affected.

  • CVE-2014-0468CriJun 26, 2025
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in fusionforge in the shipped Apache configuration, where the web server may execute scripts that the users would have uploaded in their raw SCM repositories (SVN, Git, Bzr...). This issue affects fusionforge: before 5.3+20140506.

  • CVE-2025-49603CriJun 26, 2025
    risk 0.59cvss 9.1epss 0.00

    Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control.

  • CVE-2025-30131CriJun 26, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on IROAD Dashcam FX2 devices. An unauthenticated file upload endpoint can be leveraged to execute arbitrary commands by uploading a CGI-based webshell. Once a file is uploaded, the attacker can execute commands with root privileges, gaining full control…

  • CVE-2024-52928CriJun 26, 2025
    risk 0.62cvss 9.6epss 0.00

    Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.

  • CVE-2025-34049CriJun 26, 2025
    risk 0.61cvss —epss 0.02

    An OS command injection vulnerability exists in the OptiLink ONT1GEW GPON router firmware version V2.1.11_X101 Build 1127.190306 and earlier. The router’s web management interface fails to properly sanitize user input in the target_addr parameter of the formTracert and…

  • CVE-2025-34046CriJun 26, 2025
    risk 0.65cvss —epss 0.01

    An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/index/UploadFile.php endpoint, which improperly validates uploaded files when invoked with certain parameters…

  • CVE-2025-34044CriJun 26, 2025
    risk 0.61cvss —epss 0.04

    A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute arbitrary OS…

  • CVE-2025-34043CriJun 26, 2025
    risk 0.66cvss —epss 0.08

    A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper input sanitization in the board.cgi script. The vulnerability allows unauthenticated attackers to pass arbitrary commands to the underlying operating system via…

  • CVE-2025-34042CriJun 26, 2025
    risk 0.61cvss —epss 0.02

    An authenticated command injection vulnerability exists in the Beward N100 IP Camera firmware version M2.1.6.04C014 via the ServerName and TimeZone parameters in the servetest CGI page. An attacker with access to the web interface can inject arbitrary system commands into these…

  • CVE-2025-29331CriJun 26, 2025
    risk 0.00cvss 9.8epss 0.00

    An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the management script x-ui passes the no check certificate option to wget when downloading updates

  • CVE-2025-49003CriJun 26, 2025
    risk 0.64cvss 9.8epss 0.01

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor may take advantage of a feature in Java in which the character "ı" becomes "I" when converted to uppercase, and the character "ſ" becomes "S" when converted…

  • CVE-2025-6561CriJun 26, 2025
    risk 0.64cvss 9.8epss 0.01

    Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator credentials.

  • CVE-2025-4334CriJun 26, 2025
    risk 0.57cvss 9.8epss 0.03

    The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. This makes it possible for unauthenticated…

  • CVE-2025-36038CriJun 25, 2025
    risk 0.59cvss 9.0epss 0.13

    IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.

  • CVE-2025-52483CriJun 25, 2025
    risk 0.00cvss 9.8epss 0.00

    Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities) a shell script injection can…

  • CVE-2025-52480CriJun 25, 2025
    risk 0.00cvss 9.8epss 0.01

    Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities), an argument injection is…

  • CVE-2025-49153CriJun 25, 2025
    risk 0.61cvss —epss 0.01

    The affected products could allow an unauthenticated attacker to overwrite files and execute arbitrary code.

  • CVE-2025-49151CriJun 25, 2025
    risk 0.60cvss —epss 0.01

    The affected products could allow an unauthenticated attacker to generate forged JSON Web Tokens (JWT) to bypass authentication.

  • CVE-2025-20282CriJun 25, 2025
    risk 0.66cvss 10.0epss 0.39

    A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is due a lack of file…

  • CVE-2025-20281CriKEVJun 25, 2025
    risk 0.85cvss 10.0epss 0.98

    A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This…

  • CVE-2021-4457CriJun 25, 2025
    risk 0.59cvss 9.1epss 0.00

    The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server.

  • CVE-2025-6543CriKEVJun 25, 2025
    risk 0.76cvss 9.8epss 0.11

    Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

  • CVE-2024-51978CriJun 25, 2025
    risk 0.69cvss 9.8epss 0.16

    An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request,…

  • CVE-2025-52572CriJun 24, 2025
    risk 0.65cvss 10.0epss 0.01

    Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1. Web interface does not have an authenticated session: attacker can use his own Telegram account to gain RCE to the server by authorizing in the dangling web…

  • CVE-2025-52571CriJun 24, 2025
    risk 0.55cvss 9.6epss 0.00

    Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It allows an unauthenticated attacker to gain access to Telegram account of a victim, as well as full access to the server. The issue is patched in version 1.6.2.…

  • CVE-2025-52471CriJun 24, 2025
    risk 0.00cvss 9.8epss 0.01

    ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. An integer underflow vulnerability has been identified in the ESP-NOW protocol implementation within the ESP Wi-Fi component of versions 5.4.1, 5.3.3, 5.2.5, and 5.1.6 of the ESP-IDF framework. This issue…

  • CVE-2025-49853CriJun 24, 2025
    risk 0.59cvss 9.1epss 0.00

    ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL syntax into SQL queries.

  • CVE-2025-49851CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.01

    ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability which could allow an attacker to bypass authentication and gain permissions in the product.

  • CVE-2024-37743CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.

  • CVE-2025-2566CriJun 24, 2025
    risk 0.60cvss —epss 0.01

    Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability. An unauthenticated attacker can make specially crafted requests to execute arbitrary code on the server.

  • CVE-2025-4378CriJun 24, 2025
    risk 0.65cvss 10.0epss 0.00

    Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass. This issue affects ATA-AOF Mobile Application: before 20.06.2025.

  • CVE-2025-4383CriJun 24, 2025
    risk 0.60cvss 9.3epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim Teknolojileri ve Yazılım Hizm. Tic. Ltd. Şti. Wi-Fi Cloud Hotspot allows Authentication Abuse, Authentication Bypass. This issue affects Wi-Fi Cloud Hotspot: before 30.05.2025.

  • CVE-2021-41691CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.02

    A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php.

  • CVE-2025-32977CriJun 24, 2025
    risk 0.62cvss 9.6epss 0.00

    Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unauthenticated users to upload backup files to the system. While signature…

  • CVE-2025-32975CriKEVJun 24, 2025
    risk 0.77cvss 10.0epss 0.02

    Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate…

  • CVE-2025-6433CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.00

    If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established…

  • CVE-2025-6427CriJun 24, 2025
    risk 0.59cvss 9.1epss 0.00

    An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

  • CVE-2025-6424CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.04

    A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

  • CVE-2025-50213CriJun 24, 2025
    risk 0.57cvss 9.8epss 0.01

    Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were added…

  • CVE-2025-48890CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.02

    WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in miniigd SOAP service. If a remote unauthenticated attacker sends a specially crafted request to the affected product, an arbitrary OS…

  • CVE-2025-43879CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.02

    WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in the telnet function. If a remote unauthenticated attacker sends a specially crafted request to the affected product, an arbitrary OS…