VYPR

CVEs

38,061 total · page 238 of 762

  • CVE-2025-28038CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.

  • CVE-2025-28036CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

  • CVE-2025-28035CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

  • CVE-2023-44755CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php.

  • CVE-2023-44752CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin/login.php.

  • CVE-2023-43958CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any file to the server and execute arbitrary code.

  • CVE-2025-34028CriKEVApr 22, 2025
    risk 0.85cvss 10.0epss 0.98

    The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious…

  • CVE-2025-28037CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote command execution vulnerability in the setDiagnosisCfg function through the ipDomain parameter.

  • CVE-2025-28024CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi

  • CVE-2025-1950CriApr 22, 2025
    risk 0.60cvss 9.3epss 0.00

    IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper validation of libraries of an untrusted source.

  • CVE-2025-28034CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command execution vulnerability in the…

  • CVE-2024-40446CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script

  • CVE-2024-58250CriApr 22, 2025
    risk 0.53cvss 9.3epss 0.00

    The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.

  • CVE-2025-32958CriApr 21, 2025
    risk 0.57cvss 9.8epss 0.01

    Adept is a language for general purpose programming. Prior to commit a1a41b7, the remoteBuild.yml workflow file uses actions/upload-artifact@v4 to upload the mac-standalone artifact. This artifact is a zip of the current directory, which includes the automatically generated…

  • CVE-2025-28104CriApr 21, 2025
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.

  • CVE-2025-32431CriApr 21, 2025
    risk 0.52cvss 9.1epss 0.01

    Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. In versions prior to 2.11.24, 3.3.6, and 3.4.0-rc2. There is a potential vulnerability in Traefik managing the requests using a PathPrefix, Path or PathRegex matcher. When Traefik is configured to route the…

  • CVE-2025-29660CriApr 21, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789. This service lacks proper input validation, allowing attackers to execute arbitrary scripts present on the device by sending specially crafted TCP requests…

  • CVE-2025-29659CriApr 21, 2025
    risk 0.64cvss 9.8epss 0.01

    Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.

  • CVE-2025-29287CriApr 21, 2025
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2025-0632CriApr 21, 2025
    risk 0.60cvss —epss 0.01

    Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attacker to obtain sensitive data via arbitrary code execution. A malicious actor could execute malicious scripts to automatically download configuration files in…

  • CVE-2021-4455CriApr 19, 2025
    risk 0.64cvss 9.8epss 0.01

    The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected…

  • CVE-2025-1093CriApr 19, 2025
    risk 0.64cvss 9.8epss 0.01

    The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generate_image function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected…

  • CVE-2025-3278CriApr 19, 2025
    risk 0.64cvss 9.8epss 0.01

    The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.4. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'user_register_role' field. This makes it…

  • CVE-2025-29058CriApr 18, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component.

  • CVE-2024-53591CriApr 18, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.

  • CVE-2025-28197CriApr 18, 2025
    risk 0.59cvss 9.1epss 0.00

    Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.

  • CVE-2025-28242CriApr 18, 2025
    risk 0.64cvss 9.8epss 0.02

    Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.

  • CVE-2025-28238CriApr 18, 2025
    risk 0.64cvss 9.8epss 0.00

    Improper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers to execute a session hijacking attack.

  • CVE-2025-28236CriApr 18, 2025
    risk 0.64cvss 9.8epss 0.00

    Nautel VX Series transmitters VX SW v6.4.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the firmware update process. This vulnerability allows attackers to execute arbitrary code via supplying a crafted update package to the…

  • CVE-2025-28233CriApr 18, 2025
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Version: 2, Software Version: 1.6.0, Control Version: 1.0, AIO Firmware Version: 1.7 allows attackers to access log files and extract session identifiers to…

  • CVE-2025-28231CriApr 18, 2025
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary commands with Administrator privileges.

  • CVE-2025-32434CriApr 18, 2025
    risk 0.57cvss 9.8epss 0.02

    PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using…

  • CVE-2025-29953CriApr 18, 2025
    risk 0.57cvss 9.8epss 0.02

    Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connections to untrusted servers. Such servers could abuse the unbounded deserialization in the client to…

  • CVE-2025-29209CriApr 18, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub_41105C function of cstecgi .cgi.

  • CVE-2025-28232CriApr 18, 2025
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authentication.

  • CVE-2025-28230CriApr 18, 2025
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credentials.

  • CVE-2025-28229CriApr 18, 2025
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentication and gain Administrator privileges.

  • CVE-2024-29643CriApr 18, 2025
    risk 0.59cvss 9.1epss 0.01

    An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.

  • CVE-2025-2492CriApr 18, 2025
    risk 0.60cvss —epss 0.01

    An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions. Refer to the 'ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for…

  • CVE-2025-1863CriApr 18, 2025
    risk 0.64cvss 9.8epss 0.01

    Insecure default settings have been found in recorder products provided by Yokogawa Electric Corporation. The default setting of the authentication function is disabled on the affected products. Therefore, when connected to a network with default settings, anyone can access all…

  • CVE-2025-39471CriApr 18, 2025
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pantherius Modal Survey modal-survey.This issue affects Modal Survey: from n/a through <= 2.0.2.0.1.

  • CVE-2025-42599CriKEVApr 18, 2025
    risk 0.76cvss 9.8epss 0.03

    Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition.

  • CVE-2025-28009CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.20.

  • CVE-2024-53924CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.01

    Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with the =IF(A1=200, eval("__import__('os').system( substring.

  • CVE-2025-29662CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.01

    A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system code via remote network access.

  • CVE-2025-39596CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.01

    Weak Authentication vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows Privilege Escalation.This issue affects Quentn WP: from n/a through <= 1.2.8.

  • CVE-2025-39595CriApr 17, 2025
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows SQL Injection.This issue affects Quentn WP: from n/a through <= 1.2.8.

  • CVE-2025-39588CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Object Injection.This issue affects Ultimate Store Kit Elementor Addons: from n/a through <= 2.4.0.

  • CVE-2025-39587CriApr 17, 2025
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix Cost Calculator Builder cost-calculator-builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through <= 3.2.65.

  • CVE-2025-39551CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Object Injection.This issue affects FluentBoards: from n/a through <= 1.47.