VYPR

CVEs

38,061 total · page 241 of 762

  • CVE-2025-32140CriApr 10, 2025
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail wp-remote-thumbnail allows Upload a Web Shell to a Web Server.This issue affects WP Remote Thumbnail: from n/a through <= 1.3.2.

  • CVE-2025-27690CriApr 10, 2025
    risk 0.64cvss 9.8epss 0.00

    Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to the takeover of a high privileged user account.

  • CVE-2024-58136CriKEVApr 10, 2025
    risk 0.71cvss 9.0epss 0.88

    Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

  • CVE-2024-55210CriApr 9, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via a crafted websocket message.

  • CVE-2025-3115CriApr 9, 2025
    risk 0.64cvss 9.8epss 0.01

    Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to…

  • CVE-2025-3114CriApr 9, 2025
    risk 0.61cvss —epss 0.01

    Code Execution via Malicious Files: Attackers can create specially crafted files with embedded code that may execute without adequate security validation, potentially leading to system compromise. Sandbox Bypass Vulnerability: A flaw in the TERR security mechanism allows…

  • CVE-2025-32695CriApr 9, 2025
    risk 0.64cvss 9.8epss 0.01

    Incorrect Privilege Assignment vulnerability in Mestres do WP Checkout Mestres WP checkout-mestres-wp allows Privilege Escalation.This issue affects Checkout Mestres WP: from n/a through <= 8.7.5.

  • CVE-2025-32642CriApr 9, 2025
    risk 0.65cvss 10.0epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in appsbd Vite Coupon vite-coupon allows Remote Code Inclusion.This issue affects Vite Coupon: from n/a through <= 1.0.9.

  • CVE-2025-32641CriApr 9, 2025
    risk 0.62cvss 9.6epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in anantaddons Anant Addons for Elementor anant-addons-for-elementor allows Cross Site Request Forgery.This issue affects Anant Addons for Elementor: from n/a through <= 1.1.8.

  • CVE-2025-32576CriApr 9, 2025
    risk 0.62cvss 9.6epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows Upload a Web Shell to a Web Server.This issue affects WP shop: from n/a through <= 2.6.1.

  • CVE-2025-32496CriApr 9, 2025
    risk 0.62cvss 9.6epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Uncodethemes Ultra Demo Importer ut-demo-importer allows Upload a Web Shell to a Web Server.This issue affects Ultra Demo Importer: from n/a through <= 1.0.5.

  • CVE-2025-31033CriApr 9, 2025
    risk 0.64cvss 9.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Adam Nowak Buddypress Humanity buddypress-humanity allows Cross Site Request Forgery.This issue affects Buddypress Humanity: from n/a through <= 1.2.

  • CVE-2025-31002CriApr 9, 2025
    risk 0.59cvss 9.1epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze squeeze allows Using Malicious Files.This issue affects Squeeze: from n/a through <= 1.6.

  • CVE-2025-32375CriApr 9, 2025
    risk 0.70cvss 9.8epss 0.52

    BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure deserialization in BentoML's runner server. By setting specific headers and parameters in the POST request, it is possible to execute…

  • CVE-2025-27797CriApr 9, 2025
    risk 0.64cvss 9.8epss 0.01

    OS command injection vulnerability in the specific service exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitrary OS command may be executed by a remote attacker who can log in to the product.

  • CVE-2025-32461CriApr 9, 2025
    risk 0.57cvss 9.9epss 0.01

    wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.

  • CVE-2025-30282CriApr 8, 2025
    risk 0.59cvss 9.1epss 0.02

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass…

  • CVE-2025-30281CriApr 8, 2025
    risk 0.60cvss 9.1epss 0.24

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper…

  • CVE-2025-24447CriApr 8, 2025
    risk 0.59cvss 9.1epss 0.02

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user resulting in a High impact to Confidentiality and Integrity. Exploitation…

  • CVE-2025-24446CriApr 8, 2025
    risk 0.59cvss 9.1epss 0.02

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution. Exploitation of this issue does not require user interaction, but admin panel privileges are required, and scope is…

  • CVE-2025-22871CriApr 8, 2025
    risk 0.52cvss 9.1epss 0.01

    The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.

  • CVE-2025-25226CriApr 8, 2025
    risk 0.64cvss 9.8epss 0.00

    Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the…

  • CVE-2024-48887CriApr 8, 2025
    risk 0.65cvss 9.8epss 0.16

    A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request

  • CVE-2025-32028CriApr 8, 2025
    risk 0.64cvss 9.9epss 0.02

    HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX CMS PHP application call a ’save’ function in ’HAXCMSFile.php’. This save function uses a denylist to block specific file types from being uploaded to…

  • CVE-2025-32020CriApr 8, 2025
    risk 0.53cvss —epss 0.00

    The crud-query-parser library parses query parameters from HTTP requests and converts them to database queries. Improper neutralization of the order/sort parameter in the TypeORM adapter, which allows SQL injection. You are impacted by this vulnerability if you are using the…

  • CVE-2024-54092CriApr 8, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device Kit - arm64 V1.18 (All versions), Industrial Edge Device Kit - arm64 V1.19 (All versions), Industrial Edge Device Kit - arm64 V1.20 (All versions < V1.20.2-1),…

  • CVE-2024-41794CriApr 8, 2025
    risk 0.65cvss 10.0epss 0.01

    A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). Affected devices contain hardcoded credentials for remote access to the device operating system with root privileges. This could allow unauthenticated remote attackers to gain full access to…

  • CVE-2024-41790CriApr 8, 2025
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the region parameter in specific POST requests. This could allow an authenticated remote attacker to execute arbitrary code with root…

  • CVE-2024-41789CriApr 8, 2025
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the language parameter in specific POST requests. This could allow an authenticated remote attacker to execute arbitrary code with root…

  • CVE-2024-41788CriApr 8, 2025
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the input parameters in specific GET requests. This could allow an authenticated remote attacker to execute arbitrary code with root…

  • CVE-2025-31330CriApr 8, 2025
    risk 0.64cvss 9.9epss 0.01

    SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability…

  • CVE-2025-30016CriApr 8, 2025
    risk 0.64cvss 9.8epss 0.01

    SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to which there is high impact on the Confidentiality, Integrity & Availability of the…

  • CVE-2025-27429CriApr 8, 2025
    risk 0.64cvss 9.9epss 0.01

    SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a…

  • CVE-2025-2004CriApr 8, 2025
    risk 0.52cvss 9.1epss 0.01

    The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wpe_delete_file AJAX action in all versions up to, and including, 1.8.17. This makes it possible for unauthenticated attackers to delete arbitrary…

  • CVE-2025-3363CriApr 8, 2025
    risk 0.64cvss 9.8epss 0.01

    The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.

  • CVE-2025-3362CriApr 8, 2025
    risk 0.64cvss 9.8epss 0.01

    The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.

  • CVE-2025-3361CriApr 8, 2025
    risk 0.64cvss 9.8epss 0.01

    The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.

  • CVE-2025-28413CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component

  • CVE-2025-28412CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController

  • CVE-2025-28411CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave

  • CVE-2025-28410CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges

  • CVE-2025-28408CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter

  • CVE-2025-28406CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter

  • CVE-2025-28405CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method

  • CVE-2025-28402CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter

  • CVE-2025-3248CriKEVApr 7, 2025
    risk 0.86cvss 9.8epss 1.00

    Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

  • CVE-2025-20654CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    In wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406897; Issue ID: MSV-2875.

  • CVE-2025-2941CriApr 5, 2025
    risk 0.64cvss 9.8epss 0.02

    The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the wc-upload-file[] parameter in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated…

  • CVE-2021-47667CriApr 5, 2025
    risk 0.67cvss 10.0epss 0.37

    An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to execute arbitrary commands via shell metacharacters in the tmp_name parameter when dropping off a file via a POST /dropoff request.

  • CVE-2025-32118CriApr 4, 2025
    risk 0.59cvss 9.1epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance cmp-coming-soon-maintenance allows Using Malicious Files.This issue affects CMP – Coming Soon & Maintenance: from n/a through <= 4.1.14.