VYPR

CVEs

38,061 total · page 233 of 762

  • CVE-2025-4638CriMay 14, 2025
    risk 0.00cvss 9.8epss 0.01

    A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper pointer arithmetic. Since version 1.14.0, PCL by…

  • CVE-2025-47781CriMay 14, 2025
    risk 0.64cvss 9.8epss 0.01

    Rallly is an open-source scheduling and collaboration tool. Versions up to and including 3.22.1 of the application features token based authentication. When a user attempts to login to the application, they insert their email and a 6 digit code is sent to their email address to…

  • CVE-2025-47777CriMay 14, 2025
    risk 0.00cvss 9.6epss 0.01

    5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Versions prior to 0.11.1 are vulnerable to stored cross-site scripting in chatbot responses due to insufficient sanitization. This, in turn, can lead to Remote Code Execution…

  • CVE-2024-10865CriMay 14, 2025
    risk 0.61cvss —epss 0.00

    Improper Input validation leads to XSS or Cross-site Scripting vulnerability in OpenText Advanced Authentication. This issue affects Advanced Authentication versions before 6.5.

  • CVE-2025-47436CriMay 14, 2025
    risk 0.57cvss 9.8epss 0.01

    Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompressor to allocate a 250-byte buffer but then attempts to copy 295 bytes into it.…

  • CVE-2025-47292CriMay 14, 2025
    risk 0.55cvss —epss 0.01

    Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175bdaf2be0b8102dd198, the `DebateAlternateArgumentsResolver` deserializes a `Cursor`, allowing any classes and which can be controlled by unauthenticated user.…

  • CVE-2024-24780CriMay 14, 2025
    risk 0.57cvss 9.8epss 0.01

    Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommended to upgrade to…

  • CVE-2025-3623CriMay 14, 2025
    risk 0.52cvss 9.1epss 0.01

    The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input in the automator_api_decode_message() function. This makes it possible for unauthenticated to inject a PHP…

  • CVE-2025-43567CriMay 13, 2025
    risk 0.60cvss 9.3epss 0.00

    Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse…

  • CVE-2025-43564CriMay 13, 2025
    risk 0.60cvss 9.1epss 0.15

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper…

  • CVE-2025-43563CriMay 13, 2025
    risk 0.60cvss 9.1epss 0.15

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper…

  • CVE-2025-43562CriMay 13, 2025
    risk 0.62cvss 9.1epss 0.45

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A…

  • CVE-2025-43561CriMay 13, 2025
    risk 0.60cvss 9.1epss 0.21

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass…

  • CVE-2025-43560CriMay 13, 2025
    risk 0.60cvss 9.1epss 0.19

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security…

  • CVE-2025-43559CriMay 13, 2025
    risk 0.59cvss 9.1epss 0.01

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security…

  • CVE-2025-45863CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMapDelDevice interface.

  • CVE-2025-45865CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface.

  • CVE-2025-45861CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface.

  • CVE-2025-4660CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.01

    A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-based attacker to connect…

  • CVE-2025-4658CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.00

    Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on the OpenPubkey library for authentication, this vulnerability in OpenPubkey also applies to OPKSSH versions…

  • CVE-2025-3757CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.00

    Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.

  • CVE-2025-30387CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-45858CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.11

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function.

  • CVE-2025-45857CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.01

    EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function.

  • CVE-2025-31493CriMay 13, 2025
    risk 0.52cvss 9.1epss 0.01

    Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `collection()` helper or `$kirby->collection()` method with a dynamic collection name (such as a collection name that depends…

  • CVE-2025-28056CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.00

    rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component.

  • CVE-2025-22462CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthenticated attacker to gain administrative access to the system.

  • CVE-2024-46506CriMay 13, 2025
    risk 0.73cvss 10.0epss 0.62

    NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php.

  • CVE-2025-44831CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.00

    EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.

  • CVE-2025-32756CriKEVMay 13, 2025
    risk 0.78cvss 9.8epss 0.30

    A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail…

  • CVE-2025-30159CriMay 13, 2025
    risk 0.52cvss 9.1epss 0.01

    Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `snippet()` helper or `$kirby->snippet()` method with a dynamic snippet name (such as a snippet name that depends on request…

  • CVE-2025-40628CriMay 13, 2025
    risk 0.60cvss —epss 0.00

    SQL injection vulnerability in DomainsPRO 1.2. This vulnerability could allow an attacker to retrieve, create, update and delete databases via the “d” parameter in the “/article.php” endpoint.

  • CVE-2025-33025CriMay 13, 2025
    risk 0.64cvss 9.9epss 0.01

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5),…

  • CVE-2025-33024CriMay 13, 2025
    risk 0.64cvss 9.9epss 0.01

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5),…

  • CVE-2025-32469CriMay 13, 2025
    risk 0.64cvss 9.9epss 0.01

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5),…

  • CVE-2025-26390CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in OZW672 (All versions < V6.0), OZW772 (All versions < V6.0). The web service of affected devices is vulnerable to SQL injection when checking authentication data. This could allow an unauthenticated remote attacker to bypass the check and…

  • CVE-2025-26389CriMay 13, 2025
    risk 0.65cvss 10.0epss 0.01

    A vulnerability has been identified in OZW672 (All versions < V8.0), OZW772 (All versions < V8.0). The web service in affected devices does not sanitize the input parameters required for the `exportDiagramPage` endpoint. This could allow an unauthenticated remote attacker to…

  • CVE-2025-4632CriKEVMay 13, 2025
    risk 0.78cvss 9.8epss 0.24

    Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.

  • CVE-2025-42999CriKEVMay 13, 2025
    risk 0.78cvss 9.1epss 0.14

    SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

  • CVE-2025-30012CriMay 13, 2025
    risk 0.65cvss 10.0epss 0.01

    The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attacker to send malicious payload request in a specific encoding format. The servlet will then decode this malicious request which…

  • CVE-2023-49641CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.00

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginCheck.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2025-30448CriMay 12, 2025
    risk 0.59cvss 9.1epss 0.01

    This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, visionOS 2.5. An attacker may be able to turn on sharing of an iCloud folder without…

  • CVE-2025-30436CriMay 12, 2025
    risk 0.59cvss 9.1epss 0.00

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker may be able to use Siri to enable Auto-Answer Calls.

  • CVE-2025-3659CriMay 12, 2025
    risk 0.61cvss —epss 0.00

    Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022 * Digi One SP/Digi One SP IA/Digi One IA - prior to and including…

  • CVE-2025-47682CriMay 12, 2025
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.1.

  • CVE-2025-45779CriMay 12, 2025
    risk 0.64cvss 9.8epss 0.07

    Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter.

  • CVE-2025-44830CriMay 12, 2025
    risk 0.64cvss 9.8epss 0.00

    EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.

  • CVE-2025-44022CriMay 12, 2025
    risk 0.00cvss 9.8epss 0.01

    An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism.

  • CVE-2025-26846CriMay 12, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata.

  • CVE-2024-56524CriMay 12, 2025
    risk 0.59cvss 9.1epss 0.01

    Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by adding a special character to the request.