VYPR

CVEs

38,041 total · page 224 of 761

  • CVE-2025-6427CriJun 24, 2025
    risk 0.59cvss 9.1epss 0.00

    An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

  • CVE-2025-6424CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.04

    A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

  • CVE-2025-50213CriJun 24, 2025
    risk 0.57cvss 9.8epss 0.01

    Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were added…

  • CVE-2025-48890CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.02

    WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in miniigd SOAP service. If a remote unauthenticated attacker sends a specially crafted request to the affected product, an arbitrary OS…

  • CVE-2025-43879CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.02

    WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in the telnet function. If a remote unauthenticated attacker sends a specially crafted request to the affected product, an arbitrary OS…

  • CVE-2024-56731CriJun 24, 2025
    risk 0.58cvss 10.0epss 0.01

    Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve remote command execution due to an insufficient patch for CVE-2024-39931. Unprivileged user accounts can execute arbitrary commands…

  • CVE-2025-6560CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.01

    Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator credentials.  The affected models are out of…

  • CVE-2025-6559CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.02

    Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. The affected models are out of support; replacing the device is recommended.

  • CVE-2025-48469CriJun 24, 2025
    risk 0.62cvss 9.6epss 0.00

    Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to backdoor installation or privilege escalation.

  • CVE-2025-34041CriJun 24, 2025
    risk 0.66cvss —epss 0.07

    An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the…

  • CVE-2025-34040CriJun 24, 2025
    risk 0.69cvss —epss 0.15

    An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFileType and fileId parameters are improperly validated during multipart file uploads, allowing unauthenticated attackers to upload crafted JSP files outside of…

  • CVE-2025-34039CriJun 24, 2025
    risk 0.65cvss —epss 0.01

    A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet) without proper access controls. The servlet allows unauthenticated remote attackers to execute arbitrary Java code via the…

  • CVE-2025-34037CriJun 24, 2025
    risk 0.75cvss —epss 0.93

    An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization,…

  • CVE-2025-34036CriJun 24, 2025
    risk 0.66cvss 9.8epss 0.31

    An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Server" that listens on TCP ports 81 and 82. The web interface fails to sanitize input in the URI path passed to the language extraction…

  • CVE-2025-34035CriJun 24, 2025
    risk 0.65cvss 9.8epss 0.23

    An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands.…

  • CVE-2025-52562CriJun 23, 2025
    risk 0.58cvss 10.0epss 0.02

    Convoy is a KVM server management panel for hosting businesses. In versions 3.9.0-rc3 to before 4.4.1, there is a directory traversal vulnerability in the LocaleController component of Performave Convoy. An unauthenticated remote attacker can exploit this vulnerability by…

  • CVE-2025-2828CriJun 23, 2025
    risk 0.60cvss 10.0epss 0.21

    A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain_community.agent_toolkits.openapi.toolkit.RequestsToolkit) in langchain-ai/langchain version 0.0.27. This vulnerability occurs…

  • CVE-2023-47030CriJun 23, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a GET request to a UserService SOAP API endpoint to validate if a user exists.

  • CVE-2025-6547CriJun 23, 2025
    risk 0.52cvss —epss 0.00

    Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: <=3.1.2.

  • CVE-2025-6545CriJun 23, 2025
    risk 0.52cvss —epss 0.00

    Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js. This issue affects pbkdf2: from 3.0.10 through 3.1.2.

  • CVE-2023-47029CriJun 23, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted POST request to the UserService component

  • CVE-2023-47031CriJun 23, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOrganization SOAP API component.

  • CVE-2023-47295CriJun 23, 2025
    risk 0.64cvss 9.8epss 0.01

    A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injecting a crafted payload into any text field that accepts strings.

  • CVE-2023-47032CriJun 23, 2025
    risk 0.64cvss 9.8epss 0.01

    Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the UserService SOAP API function.

  • CVE-2025-46101CriJun 23, 2025
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version before 5.4.3 allows a remote attacker to obtain sensitive information via the ks parameter in json_scorm.php file

  • CVE-2023-48978CriJun 23, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP camera URL component.

  • CVE-2023-47297CriJun 23, 2025
    risk 0.64cvss 9.8epss 0.01

    A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, including editing system security auditing configurations.

  • CVE-2025-6513CriJun 23, 2025
    risk 0.60cvss 9.3epss 0.00

    Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it.

  • CVE-2025-6512CriJun 23, 2025
    risk 0.65cvss 10.0epss 0.01

    On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server with administrator rights.

  • CVE-2025-52921CriJun 23, 2025
    risk 0.64cvss 9.9epss 0.01

    In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted file and then renaming it to have a .php extension by using the Rename Function. This bypasses the…

  • CVE-2025-52939CriJun 23, 2025
    risk 0.54cvss —epss 0.00

    Out-of-bounds Write vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with program files ldebug.C, lvm.C. This issue affects NotepadNext: through v0.11.

  • CVE-2025-52936CriJun 23, 2025
    risk 0.53cvss —epss 0.00

    Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh.This issue affects sslh: before 2.2.2.

  • CVE-2025-52935CriJun 23, 2025
    risk 0.54cvss —epss 0.00

    Integer Overflow or Wraparound vulnerability in dragonflydb dragonfly (src/redis/lua/struct modules). This vulnerability is associated with program files lua_struct.C. This issue affects dragonfly: 1.30.1, 1.30.0, 1.28.18.

  • CVE-2024-45347CriJun 23, 2025
    risk 0.62cvss 9.6epss 0.00

    An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to Unauthorized access to the victim’s device.

  • CVE-2025-52556CriJun 21, 2025
    risk 0.53cvss —epss 0.00

    rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to version 1.0.3, there is a flaw in the timestamp response signature verification logic. In particular, chain verification is performed against the TSR's embedded…

  • CVE-2025-6216CriJun 21, 2025
    risk 0.66cvss 9.8epss 0.48

    Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The specific flaw exists…

  • CVE-2025-34030CriJun 20, 2025
    risk 0.70cvss —epss 0.54

    An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php. The application fails to sanitize user-supplied input before using it in a system-level context. Remote, unauthenticated attackers can inject shell commands by…

  • CVE-2025-34022CriJun 20, 2025
    risk 0.61cvss —epss 0.01

    A path traversal vulnerability exists in multiple models of Selea Targa IP OCR-ANPR cameras, including iZero, Targa 512, Targa 504, Targa Semplice, Targa 704 TKM, Targa 805, Targa 710 INOX, Targa 750, and Targa 704 ILB. The /common/get_file.php script in the “Download Archive…

  • CVE-2025-25038CriJun 20, 2025
    risk 0.64cvss 9.8epss 0.06

    An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this…

  • CVE-2025-25037CriJun 20, 2025
    risk 0.61cvss —epss 0.02

    An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve…

  • CVE-2025-25034CriJun 20, 2025
    risk 0.64cvss —epss 0.05

    A PHP object injection vulnerability exists in SugarCRM versions prior to 6.5.24, 6.7.13, 7.5.2.5, 7.6.2.2, and 7.7.1.0 due to improper validation of PHP serialized input in the SugarRestSerialize.php script. The vulnerable code fails to sanitize the rest_data parameter before…

  • CVE-2025-49132CriJun 20, 2025
    risk 0.65cvss 10.0epss 0.54

    Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. With the ability to execute…

  • CVE-2025-44635CriJun 20, 2025
    risk 0.64cvss 9.8epss 0.01

    There are multiple unauthorized remote command execution vulnerabilities in the H3C ER2200G2, ERG2-450W, ERG2-1200W, ERG2-1350W, NR1200W series routers before ERG2AW-MNW100-R1117; H3C ER3100G2, ER3200G2, ER3260G2, ER5100G2, ER5200G2, ER6300G2, ER8300G2, ER8300G2-X series routers…

  • CVE-2025-45890CriJun 20, 2025
    risk 0.64cvss 9.8epss 0.02

    Directory Traversal vulnerability in novel plus before v.5.1.0 allows a remote attacker to execute arbitrary code via the filePath parameter

  • CVE-2025-46179CriJun 20, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was discovered in the askquery.php file of CloudClassroom-PHP Project v1.0. The squeryx parameter accepts unsanitized input, which is passed directly into backend SQL queries.

  • CVE-2025-48706CriJun 20, 2025
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in COROS PACE 3 through 3.0808.0. Due to an out-of-bounds read vulnerability, sending a crafted BLE message forces the device to reboot.

  • CVE-2025-32880CriJun 20, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. With WLAN access, the COROS Pace 3 downloads firmware files via HTTP. However, the communication is not encrypted and allows sniffing and…

  • CVE-2025-32878CriJun 20, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. This function is mainly for downloading firmware files. Before downloading firmware files, the watch requests some information about the firmware via HTTPS…

  • CVE-2025-32877CriJun 20, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on COROS PACE 3 devices through 3.0808.0. It identifies itself as a device without input or output capabilities, which results in the use of the Just Works pairing method. This method does not implement any authentication, which therefore allows…

  • CVE-2024-53298CriJun 20, 2025
    risk 0.64cvss 9.8epss 0.01

    Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS export. An unauthenticated attacker with remote access could potentially exploit this vulnerability leading to unauthorized filesystem access. The attacker may be…