VYPR

CVEs

38,050 total · page 228 of 761

  • CVE-2025-4568CriJun 5, 2025
    risk 0.60cvss —epss 0.00

    Improper neutralization of input provided by an unauthorized user into changes__reference_id parameter in URL allows for boolean-based Blind SQL Injection attacks.

  • CVE-2025-1793CriJun 5, 2025
    risk 0.57cvss 9.8epss 0.01

    Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attacker to read and write data using SQL, potentially leading to unauthorized access to data of other users depending on the usage of…

  • CVE-2025-5630CriJun 5, 2025
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. This vulnerability affects unknown code of the file /goform/form2lansetup.cgi. The manipulation of the argument ip leads to stack-based buffer overflow. The attack can be initiated remotely.…

  • CVE-2025-5624CriJun 5, 2025
    risk 0.64cvss 9.8epss 0.02

    A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been declared as critical. This vulnerability affects the function QoSPortSetup of the file /goform/QoSPortSetup. The manipulation of the argument port0_group/port0_remarker/ssid0_group/ssid0_remarker leads to…

  • CVE-2025-49008CriJun 5, 2025
    risk 0.54cvss —epss 0.01

    Atheos is a self-hosted browser-based cloud integrated development environment. Prior to version 6.0.4, improper use of `escapeshellcmd()` in `/components/codegit/traits/execute.php` allows argument injection, leading to arbitrary command execution. Atheos administrators and…

  • CVE-2025-5623CriJun 5, 2025
    risk 0.65cvss 9.8epss 0.19

    A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been classified as critical. This affects the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument dip_address/sip_address leads to stack-based buffer overflow. It is possible to…

  • CVE-2025-5622CriJun 5, 2025
    risk 0.64cvss 9.8epss 0.02

    A vulnerability was found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this issue is the function wirelessApcli_5g of the file /goform/wirelessApcli_5g. The manipulation of the argument apcli_mode_5g/apcli_enc_5g/apcli_default_key_5g leads to stack-based…

  • CVE-2025-48935CriJun 4, 2025
    risk 0.52cvss 9.1epss 0.00

    Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is possible to bypass Deno's permission read/write db permission check by using `ATTACH DATABASE` statement. Version 2.2.5 contains a patch for the issue.

  • CVE-2025-5600CriJun 4, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument LangType leads to stack-based buffer overflow. The…

  • CVE-2025-20286CriJun 4, 2025
    risk 0.64cvss 9.9epss 0.01

    A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations,…

  • CVE-2025-5598CriJun 4, 2025
    risk 0.60cvss —epss 0.00

    Path Traversal vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Retrieve Embedded Sensitive Data.This issue affects airleader MASTER: 3.0046.

  • CVE-2025-5597CriJun 4, 2025
    risk 0.65cvss —epss 0.00

    Improper Authentication vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Authentication Bypass.This issue affects airleader MASTER: 3.00571.

  • CVE-2025-4578CriJun 4, 2025
    risk 0.64cvss 9.8epss 0.01

    The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

  • CVE-2025-49223CriJun 4, 2025
    risk 0.57cvss 9.8epss 0.01

    billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2025-49002CriJun 3, 2025
    risk 0.67cvss 9.8epss 0.50

    DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohibited. The vulnerability…

  • CVE-2025-49001CriJun 3, 2025
    risk 0.65cvss 9.8epss 0.21

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any secret to forge a JWT token. The vulnerability has been fixed in v2.10.10. No known workarounds…

  • CVE-2025-48951CriJun 3, 2025
    risk 0.54cvss —epss 0.01

    Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, a threat actor could…

  • CVE-2025-23097CriJun 3, 2025
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 1380. The lack of a length check leads to out-of-bounds writes.

  • CVE-2025-32106CriJun 3, 2025
    risk 0.64cvss 9.8epss 0.01

    In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability to execute unauthorized code.

  • CVE-2025-32105CriJun 3, 2025
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow in the the Sangoma IMG2020 HTTP server through 2.3.9.6 allows an unauthenticated user to achieve remote code execution.

  • CVE-2025-45854CriJun 3, 2025
    risk 0.65cvss 10.0epss 0.03

    /server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.

  • CVE-2025-44148CriJun 3, 2025
    risk 0.68cvss 9.8epss 0.55

    Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component

  • CVE-2025-25022CriJun 3, 2025
    risk 0.62cvss 9.6epss 0.00

    IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files.

  • CVE-2025-4517CriJun 3, 2025
    risk 0.54cvss 9.4epss 0.01

    Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the…

  • CVE-2025-4797CriJun 3, 2025
    risk 0.64cvss 9.8epss 0.01

    The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.7.0. This is due to the plugin not properly validating a user's identity prior to setting an authorization cookie.…

  • CVE-2025-23099CriJun 2, 2025
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.

  • CVE-2025-5086CriKEVJun 2, 2025
    risk 0.78cvss 9.0epss 0.97

    A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.

  • CVE-2025-37096CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37095CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37093CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37092CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37090CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A server-side request forgery vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37089CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-1750CriJun 2, 2025
    risk 0.57cvss 9.8epss 0.01

    An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write arbitrary files on the server, potentially…

  • CVE-2025-0324CriJun 2, 2025
    risk 0.61cvss 9.4epss 0.00

    The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.

  • CVE-2025-49113CriKEVJun 2, 2025
    risk 0.80cvss 9.9epss 0.99

    Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

  • CVE-2025-20674CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413202;…

  • CVE-2025-20672CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00412257; Issue ID: MSV-3292.

  • CVE-2025-5408CriJun 1, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in WAVLINK QUANTUM D2G, QUANTUM D3G, WL-WN530G3A, WL-WN530HG3, WL-WN532A3 and WL-WN576K1 up to V1410_240222 and classified as critical. Affected by this issue is the function sys_login of the file /cgi-bin/login.cgi of the component HTTP POST Request…

  • CVE-2025-40908CriJun 1, 2025
    risk 0.00cvss 9.1epss 0.00

    YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified

  • CVE-2025-4631CriMay 31, 2025
    risk 0.64cvss 9.8epss 0.01

    The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stocktend_object endpoint in versions 2.0.6.0 to 2.1.1.3. This makes it possible to trigger the save_object_as_user() function for objects whose '_datatype' is set…

  • CVE-2025-4607CriMay 31, 2025
    risk 0.64cvss 9.8epss 0.01

    The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12 via the customer_registration() function. This is due to the use of a weak, low-entropy OTP mechanism in the forget() function. This makes…

  • CVE-2025-48949CriMay 30, 2025
    risk 0.57cvss 9.8epss 0.00

    Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulnerability due to improper input validation on the `role` parameter within the API endpoint `/api/artist`. Attackers can exploit this flaw to inject arbitrary SQL…

  • CVE-2025-48938CriMay 30, 2025
    risk 0.57cvss 9.8epss 0.01

    go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands on a user's machine by…

  • CVE-2023-26226CriMay 30, 2025
    risk 0.64cvss 9.8epss 0.00

    A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682

  • CVE-2025-48865CriMay 30, 2025
    risk 0.52cvss 9.1epss 0.00

    Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows clients to remove X-Forwarded headers (except X-Forwarded-For) due to a vulnerability in how it processes hop-by-hop headers. Fabio adds HTTP headers like…

  • CVE-2025-48481CriMay 30, 2025
    risk 0.64cvss 9.8epss 0.01

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated email invitation containing invite_hash, can exploit this vulnerability to self-activate their account, despite it being blocked or deleted, by leveraging the…

  • CVE-2025-47952CriMay 30, 2025
    risk 0.52cvss 9.1epss 0.01

    Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. Prior to versions 2.11.25 and 3.4.1, there is a potential vulnerability in Traefik managing the requests using a PathPrefix, Path or PathRegex matcher. When Traefik is configured to route the requests to a…

  • CVE-2025-48757CriMay 30, 2025
    risk 0.61cvss 9.3epss 0.01

    An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites. NOTE: this is disputed by the Supplier because each individual customer of the Lovable…

  • CVE-2025-44619CriMay 30, 2025
    risk 0.59cvss 9.1epss 0.00

    Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without authentication.