VYPR

CVEs

31,877 total · page 226 of 638

  • CVE-2025-64386HigOct 31, 2025
    risk 0.50cvss epss 0.00

    The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of the token can be done. This will allow an attacker with the token modify parameters of security, access or even steal the session without the legitimate and…

  • CVE-2025-64366HigOct 31, 2025
    risk 0.42cvss 7.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Blind SQL Injection.This issue affects MasterStudy LMS: from n/a through <= 3.6.27.

  • CVE-2025-64364HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Masterstudy masterstudy allows PHP Local File Inclusion.This issue affects Masterstudy: from n/a through < 4.8.126.

  • CVE-2025-64363HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SeventhQueen Kleo kleo allows PHP Local File Inclusion.This issue affects Kleo: from n/a through < 5.5.0.

  • CVE-2025-64360HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting Elementor Widgets consulting-elementor-widgets allows PHP Local File Inclusion.This issue affects Consulting Elementor Widgets: from…

  • CVE-2025-64359HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting consulting allows PHP Local File Inclusion.This issue affects Consulting: from n/a through < 6.7.5.

  • CVE-2025-64353HigOct 31, 2025
    risk 0.57cvss 8.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects Polylang: from n/a through <= 3.7.3.

  • CVE-2025-12115HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versions up to, and including, 2.1.9. This is due to the plugin not disabling the ability to name a custom price when it has been specifically disabled for a…

  • CVE-2025-11843HigOct 31, 2025
    risk 0.57cvss epss 0.00

    Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On-Premises contain an account impersonation vulnerability. A malicious user may potentially be able to impersonate the web service account or the account of a service using the API…

  • CVE-2025-30189HigOct 31, 2025
    risk 0.48cvss 7.4epss 0.01

    When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally…

  • CVE-2025-30188HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict information that is required to operate the web frontend, which leads to unavailability of the component. Please deploy the provided updates and patch releases. No…

  • CVE-2025-10897HigOct 31, 2025
    risk 0.57cvss 8.6epss 0.02

    The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php…

  • CVE-2025-7846HigOct 31, 2025
    risk 0.57cvss 8.8epss 0.01

    The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() function in all versions up to, and including, 16.7. This makes it possible for authenticated attackers, with…

  • CVE-2025-54763HigOct 31, 2025
    risk 0.47cvss 7.2epss 0.01

    FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web UI of the product may execute an arbitrary OS command.

  • CVE-2025-6176HigOct 31, 2025
    risk 0.42cvss 7.5epss 0.00

    Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less…

  • CVE-2025-52663HigOct 31, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to the UniFi Talk management network to invoke internal debug operations through the device API. …

  • CVE-2025-63423HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator password.

  • CVE-2025-61141HigOct 30, 2025
    risk 0.42cvss 7.5epss 0.01

    sqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the openEditor function passes the EDITOR environment variable and config file path to sh -c without sanitization, allowing attackers to execute arbitrary commands.

  • CVE-2025-63422HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to arbitrarily change the administrator username and password via sending a crafted GET request.

  • CVE-2025-64112HigOct 30, 2025
    risk 0.45cvss 8.0epss 0.00

    Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This…

  • CVE-2025-61196HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.00

    An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input parameter.

  • CVE-2025-61121HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by Glority Global Group Ltd., contains a credential leakage vulnerability. Improper handling of cloud service credentials may allow attackers to obtain them and carry out unauthorized…

  • CVE-2025-61120HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy), developed by IO FIT, K.K., contains improper access control vulnerabilities. Exposed credentials in traffic may allow attackers to misuse cloud resources, and predictable verification codes…

  • CVE-2025-61119HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Kanova Android App version 1.0.27 (package name com.karelane), developed by Karely L.L.C., contains improper access control vulnerabilities. Attackers may gain unauthorized access to user details and obtain group information, including entry codes, by manipulating API request…

  • CVE-2025-61114HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    2nd Line Android App version v1.2.92 and before (package name com.mysecondline.app), developed by AutoBizLine, Inc., contains an improper access control vulnerability in its authentication mechanism. The server only validates the first character of the user_token, enabling…

  • CVE-2025-12060HigOct 30, 2025
    risk 0.51cvss epss 0.01

    The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path traversal attack. The utility uses Python's tarfile.extractall function without the filter="data" feature. A remote attacker can craft a malicious tar archive…

  • CVE-2025-61118HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    mCarFix Motorists App version 2.3 (package name com.skytop.mcarfix), developed by Paniel Mwaura, contains improper access control vulnerabilities. Attackers may bypass verification to arbitrarily register accounts, and by tampering with sequential numeric IDs, gain unauthorized…

  • CVE-2025-61117HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Senza: Keto & Fasting Android App version 2.10.15 (package name com.gl.senza), developed by Paul Itoi, contains an improper access control vulnerability. By exploiting insufficient checks in user data API endpoints, attackers can obtain authentication tokens and perform account…

  • CVE-2025-61116HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    AdForest - Classified Android App version 4.0.12 (package name scriptsbundle.adforest), developed by Muhammad Jawad Arshad, contains an improper access control vulnerability in its authentication mechanism. The app uses a Base64-encoded email address as the authorization…

  • CVE-2025-61115HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    ABC Fine Wine & Spirits Android App version v.11.27.5 and before (package name com.cta.abcfinewineandspirits), developed by ABC Liquors, Inc., contains an improper access control vulnerability in its login mechanism. The application does not properly validate user passwords…

  • CVE-2025-61113HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    TalkTalk 3.3.6 Android App contains improper access control vulnerabilities in multiple API endpoints. By modifying request parameters, attackers may obtain sensitive user information (such as device identifiers and birthdays) and access private group information, including join…

  • CVE-2025-53880HigOct 30, 2025
    risk 0.57cvss epss 0.00

    A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent network to write or delete files on the filesystem with the privileges of the unprivileged wwwrun user. Although the endpoint is unauthenticated, access is…

  • CVE-2025-54470HigOct 30, 2025
    risk 0.49cvss 8.6epss 0.00

    This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVector sends anonymous telemetry data to the telemetry server. In affected versions, NeuVector does not enforce TLS certificate…

  • CVE-2025-62230HigOct 30, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a…

  • CVE-2025-62229HigOct 30, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash,…

  • CVE-2025-62231HigOct 30, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to…

  • CVE-2025-61725HigOct 29, 2025
    risk 0.42cvss 7.5epss 0.01

    The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.

  • CVE-2025-54546HigOct 29, 2025
    risk 0.49cvss 7.5epss 0.00

    On affected platforms, restricted users could use SSH port forwarding to access host-internal services

  • CVE-2025-54545HigOct 29, 2025
    risk 0.51cvss 7.8epss 0.00

    On affected platforms, a restricted user could break out of the CLI sandbox to the system shell and elevate their privileges.

  • CVE-2025-64104HigOct 29, 2025
    risk 0.40cvss 7.3epss 0.00

    LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Prior to 2.0.11, LangGraph's SQLite store implementation contains SQL injection vulnerabilities using direct string concatenation without…

  • CVE-2025-62797HigOct 29, 2025
    risk 0.56cvss epss 0.00

    FluxCP is a web-based Control Panel for rAthena servers written in PHP. A critical Cross-Site Request Forgery (CSRF) vulnerability exists in the FluxCP-based website template used by multiple rAthena/Ragnarok servers. State-changing POST endpoints accept browser-initiated…

  • CVE-2025-57227HigOct 29, 2025
    risk 0.51cvss 7.8epss 0.00

    An unquoted service path in Kingosoft Technology Ltd Kingo ROOT v1.5.8.3353 allows attackers to escalate privileges via placing a crafted executable file into a parent folder.

  • CVE-2025-11232HigOct 29, 2025
    risk 0.49cvss 7.5epss 0.00

    To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at the default setting, which is "[^A-Za-z0-9.-]"; "hostname-char-replacement" must be empty (the default); and "ddns-qualifying-suffix" must *NOT* be empty (the…

  • CVE-2025-61234HigOct 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control on Dataphone A920 v2025.07.161103 exposes a service on port 8888 by default on the local network without authentication. This allows an attacker to interact with the device via a TCP socket without credentials. Additionally, sending an HTTP request to…

  • CVE-2025-60595HigOct 29, 2025
    risk 0.53cvss 8.2epss 0.00

    SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution.

  • CVE-2024-14012HigOct 29, 2025
    risk 0.47cvss epss 0.00

    Potential privilege escalation issue in Revenera InstallShield version 2023 R1 running a renamed Setup.exe on Windows. When a local administrator executes a renamed Setup.exe, the MPR.dll may get loaded from an insecure location and can result in a privilege escalation. The…

  • CVE-2025-61429HigOct 29, 2025
    risk 0.57cvss 8.8epss 0.00

    An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request.

  • CVE-2025-61156HigOct 29, 2025
    risk 0.51cvss 7.8epss 0.00

    Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privileges and execute arbitrary commands via an insecure IOCTL.

  • CVE-2025-10932HigOct 29, 2025
    risk 0.53cvss 8.2epss 0.00

    Uncontrolled Resource Consumption vulnerability in Progress MOVEit Transfer (AS2 module).This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.3, from 2024.1.0 before 2024.1.7, from 2023.1.0 before 2023.1.16.

  • CVE-2025-61161HigOct 29, 2025
    risk 0.55cvss 8.4epss 0.00

    DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an uncontrolled search path (C:\ProgramData\Evope). This allows local unprivileged attackers to execute arbitrary code or escalate privileges to SYSTEM by placing a…