VYPR

CVEs

31,889 total · page 233 of 638

  • CVE-2025-11177HigOct 15, 2025
    risk 0.49cvss 7.5epss 0.00

    The External Login plugin for WordPress is vulnerable to SQL Injection via the 'log' parameter in all versions up to, and including, 1.11.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

  • CVE-2025-10754HigOct 15, 2025
    risk 0.47cvss 7.2epss 0.01

    The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Editor-level access…

  • CVE-2025-10743HigOct 15, 2025
    risk 0.49cvss 7.5epss 0.00

    The Outdoor plugin for WordPress is vulnerable to SQL Injection via the 'edit' action in all versions up to, and including, 1.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…

  • CVE-2025-10313HigOct 15, 2025
    risk 0.47cvss 7.2epss 0.00

    The Find And Replace content for WordPress plugin for WordPress is vulnerable to unauthorized Stored Cross-Site Scripting and Arbitrary Content Replacement due to a missing capability check on the far_admin_ajax_fun() function in all versions up to, and including, 1.1. This…

  • CVE-2025-10299HigOct 15, 2025
    risk 0.57cvss 8.8epss 0.00

    The WPBifröst – Instant Passwordless Temporary Login Links plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ctl_create_link AJAX action in all versions up to, and including, 1.0.7. This makes it possible for authenticated…

  • CVE-2025-10293HigOct 15, 2025
    risk 0.57cvss 8.8epss 0.00

    The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity associated with a token generated. This…

  • CVE-2025-10051HigOct 15, 2025
    risk 0.47cvss 7.2epss 0.01

    The Demo Import Kit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.1.0 via the import functionality. This makes it possible for authenticated attackers, with Administrator-level access and…

  • CVE-2025-61941HigOct 15, 2025
    risk 0.47cvss 7.2epss 0.00

    A path traversal issue exists in WXR9300BE6P series firmware versions prior to Ver.1.10. Arbitrary file may be altered by an administrative user who logs in to the affected product. Moreover, arbitrary OS command may be executed via some file alteration.

  • CVE-2025-11501HigOct 15, 2025
    risk 0.49cvss 7.5epss 0.00

    The Dynamically Display Posts plugin for WordPress is vulnerable to SQL Injection via the 'tax_query' parameter in all versions up to, and including, 1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. …

  • CVE-2025-6042HigOct 15, 2025
    risk 0.47cvss 7.3epss 0.00

    The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.4.0. This is due to the plugin assigning the editor role by default. While limitations with…

  • CVE-2025-26861HigOct 15, 2025
    risk 0.51cvss 7.8epss 0.00

    RemoteCall Remote Support Program (for Operator) versions prior to 5.3.0 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution.

  • CVE-2025-26860HigOct 15, 2025
    risk 0.51cvss 7.8epss 0.00

    RemoteCall Remote Support Program (for Operator) versions prior to 5.1.0 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution.

  • CVE-2025-26859HigOct 15, 2025
    risk 0.51cvss 7.8epss 0.00

    RemoteView PC Application Console versions prior to 6.0.2 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution.

  • CVE-2025-11746HigOct 15, 2025
    risk 0.57cvss 8.8epss 0.01

    The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.5.4 via theet_ajax_required_plugins_popup() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute…

  • CVE-2024-13991HigOct 15, 2025
    risk 0.57cvss epss 0.00

    Huijietong Cloud Video Platform contains a path traversal vulnerability that allows an unauthenticated attacker can supply arbitrary file paths to the `fullPath` parameter of the `/fileDownload?action=downloadBackupFile` endpoint and retrieve files from the server…

  • CVE-2025-49552HigOct 14, 2025
    risk 0.53cvss 8.1epss 0.00

    Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a high-privileged attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a…

  • CVE-2025-61678HigOct 14, 2025
    risk 0.60cvss epss 0.50

    FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains an authenticated arbitrary file upload vulnerability affecting…

  • CVE-2025-61675HigOct 14, 2025
    risk 0.59cvss epss 0.39

    FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains authenticated SQL injection vulnerabilities affecting multiple…

  • CVE-2025-59051HigOct 14, 2025
    risk 0.56cvss epss 0.01

    The FreePBX Endpoint Manager module includes a Network Scanning feature that provides web-based access to nmap functionality for network device discovery. In Endpoint Manager 16 before 16.0.92 and 17 before 17.0.6, insufficiently sanitized user-supplied input allows…

  • CVE-2025-33182HigOct 14, 2025
    risk 0.49cvss 7.6epss 0.00

    NVIDIA Jetson Linux contains a vulnerability in UEFI, where improper authentication may allow a privileged user to cause corruption of the Linux Device Tree. A successful exploitation of this vulnerability might lead to data tampering, denial of service.

  • CVE-2025-60536HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in the Configure New Cluster interface of kafka-ui v0.6.0 to v0.7.2 allows attackers to cause a Denial of Service (DoS) via uploading a crafted configuration file.

  • CVE-2025-57618HigOct 14, 2025
    risk 0.48cvss 7.3epss 0.01

    A path traversal vulnerability in FastX3 thru 3.3.67 allows an unauthenticated attacker to read arbitrary files on the server. By leveraging this vulnerability, it is possible to access the application's configuration files, which contain the secret key used to sign JSON Web…

  • CVE-2025-23356HigOct 14, 2025
    risk 0.55cvss 8.4epss 0.00

    NVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

  • CVE-2025-11736HigOct 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /index.php. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2025-60535HigOct 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to execute arbitrary operations via a crafted GET request.

  • CVE-2025-59249HigOct 14, 2025
    risk 0.57cvss 8.8epss 0.01

    Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-59248HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-59234HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-59227HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-53782HigOct 14, 2025
    risk 0.55cvss 8.4epss 0.00

    Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-37147HigOct 14, 2025
    risk 0.46cvss 7.1epss 0.00

    A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root of trust verification in place to ensure only vendor-signed firmware can execute on the device. An adversary can exploit this vulnerability to run modified or…

  • CVE-2025-37146HigOct 14, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the web-based management interface of network access point configuration services could allow an authenticated remote attacker to perform remote command execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying…

  • CVE-2025-62172HigOct 14, 2025
    risk 0.55cvss epss 0.01

    Home Assistant is open source home automation software that puts local control and privacy first. In versions 2025.1.0 through 2025.10.1, the energy dashboard is vulnerable to stored cross-site scripting. An authenticated user can inject malicious JavaScript code into an energy…

  • CVE-2025-57740HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions,…

  • CVE-2025-25253HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.00

    An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions…

  • CVE-2025-11577HigOct 14, 2025
    risk 0.49cvss 7.6epss 0.00

    Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected…

  • CVE-2025-33044HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local means. Successful exploitation of this vulnerability may lead to memory corruption and impact Integrity and Availability.

  • CVE-2025-22832HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and loss of availability.

  • CVE-2025-22831HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and loss of availability.

  • CVE-2025-9178HigOct 14, 2025
    risk 0.50cvss epss 0.00

    A denial-of-service security issue exists in the affected product and version. The security issue is caused through CIP communication using crafted payloads. The security issue could result in no CIP communication with 1715 EtherNet/IP Adapter.A restart is required to recover.

  • CVE-2025-9177HigOct 14, 2025
    risk 0.50cvss epss 0.00

    A denial-of-service security issue exists in the affected product and version. The security issue stems from a high number of requests sent to the web server. This could result in a web server crash however; this does not impact I/O control or communication . A power cycle is…

  • CVE-2025-9124HigOct 14, 2025
    risk 0.57cvss epss 0.00

    A denial-of-service security issue in the affected product. The security issue stems from a fault occurring when a crafted CIP unconnected explicit message is sent. This can result in a major non-recoverable fault.

  • CVE-2025-9066HigOct 14, 2025
    risk 0.57cvss epss 0.00

    A security issue was discovered within FactoryTalk® ViewPoint, allowing unauthenticated attackers to achieve XXE. Certain SOAP requests can be abused to perform XXE, resulting in a temporary denial-of-service.

  • CVE-2025-11720HigOct 14, 2025
    risk 0.53cvss 8.1epss 0.00

    The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of…

  • CVE-2025-11715HigOct 14, 2025
    risk 0.57cvss 8.8epss 0.00

    Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This…

  • CVE-2025-11714HigOct 14, 2025
    risk 0.57cvss 8.8epss 0.00

    Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary…

  • CVE-2025-11713HigOct 14, 2025
    risk 0.53cvss 8.1epss 0.00

    Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4,…

  • CVE-2025-9437HigOct 14, 2025
    risk 0.57cvss epss 0.00

    A security issue exists within the Studio 5000 Logix Designer add-on profile (AOP) for the ArmorStart Classic distributed motor controller, resulting in denial-of-service. This vulnerability is possible due to the input of invalid values into Component Object Model (COM) methods.

  • CVE-2025-10228HigOct 14, 2025
    risk 0.57cvss 8.8epss 0.00

    Session Fixation vulnerability in Rolantis Information Technologies Agentis allows Session Hijacking. This issue affects Agentis: before 4.44.

  • CVE-2011-20002HigOct 14, 2025
    risk 0.48cvss 7.4epss 0.00

    A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) (All versions < V2.0.2). Affected controllers are vulnerable to capture-replay in the communication with…