VYPR

CVEs

31,889 total · page 238 of 638

  • CVE-2025-11153HigSep 30, 2025
    risk 0.49cvss 7.5epss 0.00

    JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3.

  • CVE-2025-11152HigSep 30, 2025
    risk 0.56cvss 8.6epss 0.00

    Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143.0.3.

  • CVE-2025-9993HigSep 30, 2025
    risk 0.53cvss 8.1epss 0.01

    The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the 'task'. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute…

  • CVE-2025-9991HigSep 30, 2025
    risk 0.53cvss 8.1epss 0.01

    The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.3.34 via the 'language' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server,…

  • CVE-2025-8877HigSep 30, 2025
    risk 0.49cvss 7.5epss 0.00

    The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the ajax_get_affiliate_id_from_login function in all versions up to, and including, 2.28.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

  • CVE-2025-7052HigSep 30, 2025
    risk 0.50cvss 8.8epss 0.00

    The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.94. This is due to missing nonce validation on the change_password() function of its customer_cabinet__change_password AJAX route. The plugin hooks this…

  • CVE-2025-7038HigSep 30, 2025
    risk 0.53cvss 8.2epss 0.00

    The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification within the steps__load_step route of the latepoint_route_call AJAX endpoint in all versions up to, and including, 5.1.94. The endpoint reads the client-supplied…

  • CVE-2025-59668HigSep 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Multiple versions of Central Monitor CNS-6201 contain a NULL pointer dereference vulnerability. When processing a crafted certain UDP packet, the affected device may abnormally terminate.

  • CVE-2025-11149HigSep 30, 2025
    risk 0.42cvss 7.5epss 0.01

    This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server.

  • CVE-2025-10991HigSep 30, 2025
    risk 0.46cvss epss 0.00

    The attacker may obtain root access by connecting to the UART port and this vulnerability requires the attacker to have the physical access to the device. This issue affects Tapo D230S1 V1.20: before 1.2.2 Build 20250907.

  • CVE-2025-59952HigSep 30, 2025
    risk 0.50cvss epss 0.00

    MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service. In minio-java versions prior to 8.6.0, XML tag values containing references to system properties or environment variables were…

  • CVE-2025-57424HigSep 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within the LTA number profile field. An attacker can insert arbitrary JavaScript into their profile, which executes in the browser of any user viewing it, including administrators. Due to the…

  • CVE-2025-41252HigSep 29, 2025
    risk 0.49cvss 7.5epss 0.01

    Description: VMware NSX contains a username enumeration vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially leading to unauthorized access attempts. Impact: Username enumeration → facilitates unauthorized access. …

  • CVE-2025-41251HigSep 29, 2025
    risk 0.53cvss 8.1epss 0.01

    VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially enabling brute-force attacks. Impact: Username enumeration → credential brute force risk. Attack…

  • CVE-2025-57483HigSep 29, 2025
    risk 0.53cvss 8.1epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the vulnerable parameter.

  • CVE-2025-41250HigSep 29, 2025
    risk 0.55cvss 8.5epss 0.01

    VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.

  • CVE-2025-56234HigSep 29, 2025
    risk 0.49cvss 7.5epss 0.00

    AT_NA2000 from Nanda Automation Technology vendor has a denial-of-service vulnerability. For the processing of TCP RST packets, PLC AT_NA2000 has a wide acceptable range of sequence numbers. It does not require the sequence number to exactly match the next expected sequence…

  • CVE-2025-56233HigSep 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Openindiana, kernel SunOS 5.11 has a denial of service vulnerability. For the processing of TCP packets with RST or SYN flag set, Openindiana has a wide acceptable range of sequence numbers. It does not require the sequence number to exactly match the next expected sequence…

  • CVE-2024-57412HigSep 29, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP packets.

  • CVE-2025-41246HigSep 29, 2025
    risk 0.49cvss 7.6epss 0.00

    VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access…

  • CVE-2025-56449HigSep 29, 2025
    risk 0.53cvss 8.2epss 0.00

    A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out due to not enrolling in MFA (e.g. after the 7-day enforcement window), the REST API still allows the use of Basic Authentication to authenticate and perform…

  • CVE-2025-9648HigSep 29, 2025
    risk 0.57cvss epss 0.01

    A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTTP POST request containing a null byte in the payload, the server enters an infinite loop during…

  • CVE-2025-11140HigSep 29, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this vulnerability is the function openForm of the component com.artery.richclient.RichClientService. Such manipulation of the argument contentString leads to xml external entity reference. The attack…

  • CVE-2025-11135HigSep 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486. The affected element is the function loadLanguage of the file classes/class.database.php of the component Cookie Handler. Performing manipulation of the argument…

  • CVE-2025-11130HigSep 29, 2025
    risk 0.55cvss 8.4epss 0.00

    A weakness has been identified in iHongRen pptp-vpn 1.0/1.0.1 on macOS. This issue affects the function shouldAcceptNewConnection of the file HelpTool/HelperTool.m of the component XPC Service. This manipulation causes missing authentication. The attack can only be executed…

  • CVE-2025-11118HigSep 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in CodeAstro Student Grading System 1.0. This issue affects some unknown processing of the file /adminLogin.php. Such manipulation of the argument staffId leads to sql injection. The attack may be performed from remote. The exploit is publicly…

  • CVE-2025-11116HigSep 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Simple Scheduling System 1.0. This affects an unknown part of the file /add.home.php. The manipulation of the argument faculty results in sql injection. The attack can be executed remotely. The exploit has been made public and could be…

  • CVE-2025-11115HigSep 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in code-projects Simple Scheduling System 1.0. Affected by this issue is some unknown functionality of the file /addtime.php. The manipulation of the argument starttime/endtime leads to sql injection. Remote exploitation of the attack is possible.…

  • CVE-2025-11111HigSep 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This affects an unknown function of the file /admin/candidates_edit.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has…

  • CVE-2025-11110HigSep 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in Campcodes Online Learning Management System 1.0. The impacted element is an unknown function of the file /admin/school_year.php. The manipulation of the argument school_year results in sql injection. It is possible to launch the attack…

  • CVE-2025-11109HigSep 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/us_edit.php?action=edit. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack…

  • CVE-2025-11108HigSep 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in code-projects Simple Scheduling System 1.0. Impacted is an unknown function of the file /schedulingsystem/addroom.php. Executing manipulation of the argument room can lead to sql injection. The attack may be performed from remote. The exploit…

  • CVE-2025-11107HigSep 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Simple Scheduling System 1.0. This issue affects some unknown processing of the file /schedulingsystem/addcourse.php. Performing manipulation of the argument corcode results in sql injection. The attack is possible to be carried out…

  • CVE-2025-11106HigSep 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in code-projects Simple Scheduling System 1.0. This vulnerability affects unknown code of the file /schedulingsystem/addfaculty.php. Such manipulation of the argument falname leads to sql injection. The attack can be executed remotely. The exploit…

  • CVE-2025-11105HigSep 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in code-projects Simple Scheduling System 1.0. This affects an unknown part of the file /schedulingsystem/addsubject.php. This manipulation of the argument subcode causes sql injection. Remote exploitation of the attack is possible. The exploit has been…

  • CVE-2025-11102HigSep 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/edit_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be launched remotely. The exploit has…

  • CVE-2025-11101HigSep 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in itsourcecode Open Source Job Portal 1.0. This impacts an unknown function of the file /jobportal/admin/company/index.php?view=edit. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely.…

  • CVE-2025-11094HigSep 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in code-projects E-Commerce Website 1.0. This affects an unknown part of the file /pages/admin_product_details.php. Such manipulation of the argument prod_id leads to sql injection. The attack may be launched remotely. The exploit has…

  • CVE-2025-11089HigSep 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. This impacts an unknown function of the file /Profilers/PriProfile/COUNT3s4.php. Executing manipulation of the argument cbranch can lead to sql injection. It is…

  • CVE-2025-11077HigSep 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/add_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be executed remotely. The exploit has…

  • CVE-2025-11076HigSep 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Campcodes Online Learning Management System 1.0. This impacts an unknown function of the file /admin/edit_teacher.php. Performing manipulation of the argument department results in sql injection. Remote exploitation of the attack is possible. The…

  • CVE-2025-11075HigSep 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Campcodes Online Learning Management System 1.0. This affects an unknown function of the file /admin/de_activate.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been…

  • CVE-2025-11074HigSep 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /login.php. This manipulation of the argument username/password causes sql injection. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-7647HigSep 27, 2025
    risk 0.40cvss 7.3epss 0.00

    The llama-index-core package, up to version 0.12.44, contains a vulnerability in the `get_cache_dir()` function where a predictable, hardcoded directory path `/tmp/llama_index` is used on Linux systems without proper security controls. This vulnerability allows attackers on…

  • CVE-2025-11070HigSep 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in Projectworlds Online Shopping System 1.0. This affects an unknown part of the file /store/cart_add.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and…

  • CVE-2025-11066HigSep 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in code-projects Online Bidding System 1.0. This impacts an unknown function of the file /administrator/bidlist.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and…

  • CVE-2025-11064HigSep 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in Campcodes Online Learning Management System 1.0. Impacted is an unknown function of the file /admin/teachers.php. The manipulation of the argument department results in sql injection. It is possible to launch the attack remotely. The…

  • CVE-2025-11063HigSep 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in Campcodes Online Learning Management System 1.0. This issue affects some unknown processing of the file /admin/edit_department.php. The manipulation of the argument d leads to sql injection. It is possible to initiate the attack remotely. The…

  • CVE-2025-11062HigSep 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in Campcodes Online Learning Management System 1.0. This vulnerability affects unknown code of the file /admin/save_student.php. Executing manipulation of the argument class_id can lead to sql injection. The attack may be performed from remote. The…

  • CVE-2025-11061HigSep 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Campcodes Online Learning Management System 1.0. This affects an unknown part of the file /admin/edit_student.php. Performing manipulation of the argument cys results in sql injection. The attack is possible to be carried out remotely. The exploit…