VYPR

CVEs

38,061 total · page 234 of 762

  • CVE-2024-56523CriMay 12, 2025
    risk 0.59cvss 9.1epss 0.01

    Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by placing random data in the HTTP request body when using the HTTP GET method.

  • CVE-2025-4559CriMay 12, 2025
    risk 0.64cvss 9.8epss 0.01

    The ISOinsight from Netvision has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

  • CVE-2025-4558CriMay 12, 2025
    risk 0.64cvss 9.8epss 0.01

    The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.

  • CVE-2025-4557CriMay 12, 2025
    risk 0.59cvss 9.1epss 0.01

    The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific APIs and operate system functions. These functions include opening gates and restarting the system.

  • CVE-2025-4556CriMay 12, 2025
    risk 0.64cvss 9.8epss 0.01

    The web management interface of Okcat Parking Management Platform from ZONG YU has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

  • CVE-2025-4555CriMay 12, 2025
    risk 0.64cvss 9.8epss 0.01

    The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access system functions. These functions include opening gates, viewing license plates and parking…

  • CVE-2025-46192CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.00

    SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter.

  • CVE-2025-46191CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and…

  • CVE-2025-46190CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.00

    SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter.

  • CVE-2025-46193CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php.

  • CVE-2025-46189CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter.

  • CVE-2025-46188CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.

  • CVE-2025-45513CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.

  • CVE-2025-28200CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.

  • CVE-2025-45887CriMay 9, 2025
    risk 0.59cvss 9.1epss 0.00

    Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent.

  • CVE-2025-45885CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Attackers can inject malicious code from the parameter 'emailcont' and use it directly in SQL queries.

  • CVE-2024-12442CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote shell access.

  • CVE-2024-11861CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access.

  • CVE-2025-1087CriMay 9, 2025
    risk 0.54cvss —epss 0.01

    Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to…

  • CVE-2025-4403CriMay 9, 2025
    risk 0.57cvss 9.8epss 0.02

    The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.1.6 due to accepting a user‐supplied supported_type string and the uploaded filename without enforcing real extension or…

  • CVE-2025-3605CriMay 9, 2025
    risk 0.67cvss 9.8epss 0.07

    The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email…

  • CVE-2025-37879CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: 9p/net: fix improper handling of bogus negative read/write replies In p9_client_write() and p9_client_read_once(), if the server incorrectly replies with success but a negative write/read count then we would…

  • CVE-2025-2253CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    The IMITHEMES Listing plugin is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3. This is due to the plugin not properly validating a verification code value prior to updating their password through the imic_reset_password_init()…

  • CVE-2024-11617CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'zetra_languageUpload' and 'zetra_fontsUpload' functions in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to…

  • CVE-2025-3463CriMay 9, 2025
    risk 0.61cvss —epss 0.01

    "This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insufficient validation vulnerability in ASUS DriverHub may allow untrusted sources to affect system behavior via crafted HTTP requests. Refer to the 'Security Update…

  • CVE-2025-3714CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.02

    The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.

  • CVE-2025-3711CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.02

    The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.

  • CVE-2025-3710CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.02

    The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.

  • CVE-2025-3811CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like email through the…

  • CVE-2025-3810CriMay 9, 2025
    risk 0.57cvss 9.8epss 0.01

    The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password and email through the…

  • CVE-2025-47733CriMay 8, 2025
    risk 0.59cvss 9.1epss 0.02

    Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network

  • CVE-2025-29972CriMay 8, 2025
    risk 0.65cvss 9.9epss 0.04

    Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.

  • CVE-2025-29827CriMay 8, 2025
    risk 0.64cvss 9.9epss 0.02

    Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-29813CriMay 8, 2025
    risk 0.65cvss 10.0epss 0.02

    Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2023-31585CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    Grocery-CMS-PHP-Restful-API v1.3 is vulnerable to File Upload via /admin/add-category.php.

  • CVE-2025-45798CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in the setNoticeCfg interface within the /lib/cste_modules/system.so library, specifically in the processing of the IpTo parameter.

  • CVE-2025-45797CriMay 8, 2025
    risk 0.65cvss 9.8epss 0.18

    TOTOlink A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the NoticeUrl parameter in the setNoticeCfg interface of /lib/cste_modules/system.so.

  • CVE-2025-45790CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMacQos interface of /lib/cste_modules/firewall.so.

  • CVE-2025-45789CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParentalRules.

  • CVE-2025-45788CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules.

  • CVE-2025-45787CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow viathe comment parameter in setIpPortFilterRules.

  • CVE-2025-0505CriMay 8, 2025
    risk 0.65cvss 10.0epss 0.01

    On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state for devices under…

  • CVE-2024-12378CriMay 8, 2025
    risk 0.59cvss 9.1epss 0.01

    On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.

  • CVE-2024-11186CriMay 8, 2025
    risk 0.65cvss 10.0epss 0.01

    On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premise. It does not impact…

  • CVE-2025-26845CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the backup.pl script.

  • CVE-2025-45841CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.

  • CVE-2025-26844CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.

  • CVE-2025-3476CriMay 7, 2025
    risk 0.61cvss —epss 0.00

    Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege escalation by authenticated users.This issue affects Operations Bridge Manager: 2023.05, 23.4, 24.2, 24.4.

  • CVE-2025-46828CriMay 7, 2025
    risk 0.00cvss 9.8epss 0.01

    WeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in versions up to and including 3.3.0 in the endpoint `/html/socio/sistema/get_socios.php`, specifically in the query parameter. This issue allows attackers to…

  • CVE-2025-20188CriMay 7, 2025
    risk 0.66cvss 10.0epss 0.27

    A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to…