VYPR

CVEs

38,065 total · page 254 of 762

  • CVE-2025-25196CriFeb 19, 2025
    risk 0.57cvss 9.8epss 0.00

    OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, docker < v.1.8.4) are vulnerable to authorization bypass when certain Check and ListObject calls are…

  • CVE-2023-46271CriFeb 19, 2025
    risk 0.64cvss 9.8epss 0.01

    Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has a buffer overflow. This issue arises from the ah_webui service, which listens on TCP port 3009 by default.

  • CVE-2020-35546CriFeb 19, 2025
    risk 0.59cvss 9.1epss 0.00

    Lexmark MX6500 LW75.JD.P296 and previous devices have Incorrect Access Control via the access control settings.

  • CVE-2025-25467CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted AAC file.

  • CVE-2025-26617CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `historico_paciente.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries,…

  • CVE-2025-26615CriFeb 18, 2025
    risk 0.65cvss 10.0epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the WeGIA application, `examples.php` endpoint. This vulnerability could allow an attacker to gain unauthorized access to sensitive…

  • CVE-2025-26613CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.03

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection vulnerability was discovered in the WeGIA application, `gerenciar_backup.php` endpoint. This vulnerability could allow an attacker to execute arbitrary code…

  • CVE-2025-26612CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `adicionar_almoxarife.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL…

  • CVE-2025-26611CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `remover_produto.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries,…

  • CVE-2025-26610CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `restaurar_produto_desocultar.php` endpoint. This vulnerability allow an authorized attacker to execute…

  • CVE-2025-26609CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `familiar_docfamiliar.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL…

  • CVE-2025-26608CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `dependente_docdependente.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL…

  • CVE-2025-26607CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `documento_excluir.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries,…

  • CVE-2025-26606CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `informacao_adicional.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL…

  • CVE-2025-26623CriFeb 18, 2025
    risk 0.57cvss 9.8epss 0.01

    Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A heap buffer overflow was found in Exiv2 versions v0.28.0 to v0.28.4. Versions prior to v0.28.0, such as v0.27.7, are **not** affected. Exiv2 is a…

  • CVE-2025-22654CriFeb 18, 2025
    risk 0.65cvss 10.0epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified simplified allows Using Malicious Files.This issue affects Simplified: from n/a through <= 1.0.6.

  • CVE-2024-56000CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issue affects K Elements: from n/a through < 5.4.0.

  • CVE-2025-24895CriFeb 18, 2025
    risk 0.52cvss 9.1epss 0.01

    CIE.AspNetCore.Authentication is an AspNetCore Remote Authenticator for CIE 3.0. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: 1. Identity Provider (IDP): the system that authenticates users and provides identity information (SAML…

  • CVE-2025-24894CriFeb 18, 2025
    risk 0.52cvss 9.1epss 0.01

    SPID.AspNetCore.Authentication is an AspNetCore Remote Authenticator for SPID. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: Identity Provider (IDP): the system that authenticates users and provides identity information (SAML…

  • CVE-2024-55460CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attackers to execute arbitrary code via a crafted input.

  • CVE-2024-39327CriFeb 18, 2025
    risk 0.64cvss 9.9epss 0.00

    Incorrect Access Control vulnerability in Atos Eviden IDRA before 2.6.1 could allow the possibility to obtain CA signing in an illegitimate way.

  • CVE-2024-57045CriFeb 18, 2025
    risk 0.66cvss 9.8epss 0.32

    A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.

  • CVE-2025-1023CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.02

    A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functionality. The newCountName parameter is directly concatenated into an SQL…

  • CVE-2024-12860CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.00

    The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token prior to updating a user's password. This…

  • CVE-2024-13725CriFeb 18, 2025
    risk 0.57cvss 9.8epss 0.01

    The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.1 via the service parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any…

  • CVE-2025-25222CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.00

    The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in retrieve.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved.

  • CVE-2025-25221CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.00

    The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in pdf.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved.

  • CVE-2021-46686CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in acmailer CGI ver.4.0.3 and earlier and acmailer DB ver.1.1.5 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker.

  • CVE-2025-1387CriFeb 17, 2025
    risk 0.64cvss 9.8epss 0.01

    Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user.

  • CVE-2025-22290CriFeb 16, 2025
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology LTL Freight Quotes – FreightQuote Edition ltl-freight-quotes-freightquote-edition allows SQL Injection.This issue affects LTL Freight Quotes – FreightQuote…

  • CVE-2024-57971CriFeb 16, 2025
    risk 0.52cvss 9.1epss 0.01

    DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occurs at the beginning of a JNDI Name.

  • CVE-2025-26793CriFeb 15, 2025
    risk 0.61cvss —epss 0.02

    The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not prompted to change these credentials on initial configuration, and changing the…

  • CVE-2024-12562CriFeb 15, 2025
    risk 0.64cvss 9.8epss 0.01

    The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216 via deserialization of untrusted input from the 's2member_pro_remote_op' vulnerable parameter. This makes it possible for unauthenticated attackers to inject…

  • CVE-2024-13513CriFeb 15, 2025
    risk 0.64cvss 9.8epss 0.01

    The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2.3 via the logging functionality. This makes it possible for unauthenticated attackers to extract sensitive data…

  • CVE-2025-1302CriFeb 15, 2025
    risk 0.58cvss 9.8epss 0.10

    Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by…

  • CVE-2024-4282CriFeb 15, 2025
    risk 0.64cvss 9.8epss 0.00

    Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22.

  • CVE-2025-26508CriFeb 14, 2025
    risk 0.64cvss 9.8epss 0.01

    Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.

  • CVE-2025-26507CriFeb 14, 2025
    risk 0.64cvss 9.8epss 0.01

    Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.

  • CVE-2025-26506CriFeb 14, 2025
    risk 0.64cvss 9.8epss 0.01

    Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.

  • CVE-2024-56973CriFeb 14, 2025
    risk 0.64cvss 9.8epss 0.01

    Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary code via the source and filename parameters to the ProcessUploadFromURL.jsp component.

  • CVE-2024-56180CriFeb 14, 2025
    risk 0.57cvss 9.8epss 0.01

    CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via hessian deserialization…

  • CVE-2025-0867CriFeb 14, 2025
    risk 0.64cvss 9.9epss 0.01

    The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were stored. Consequently, the EPC2 user can execute any command with administrative…

  • CVE-2024-13152CriFeb 14, 2025
    risk 0.65cvss 10.0epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy Online Machinery Monitoring Panel allows SQL Injection. This issue affects Mobuy Online Machinery Monitoring Panel: before 2.0.

  • CVE-2024-52577CriFeb 14, 2025
    risk 0.52cvss 9.0epss 0.03

    In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an attacker manually crafts an Ignite message containing a vulnerable object whose class is present in…

  • CVE-2025-1298CriFeb 14, 2025
    risk 0.64cvss 9.8epss 0.00

    Logic vulnerability in the mobile application (com.transsion.carlcare) may lead to the risk of account takeover.

  • CVE-2025-22630CriFeb 14, 2025
    risk 0.64cvss 9.9epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Marketing Fire Widget Options widget-options allows OS Command Injection.This issue affects Widget Options: from n/a through <= 4.1.0.

  • CVE-2025-25067CriFeb 13, 2025
    risk 0.64cvss 9.8epss 0.02

    mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.

  • CVE-2025-24865CriFeb 13, 2025
    risk 0.69cvss 10.0epss 0.07

    The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.

  • CVE-2025-1283CriFeb 13, 2025
    risk 0.64cvss 9.8epss 0.01

    The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly navigating to the main page.

  • CVE-2023-34399CriFeb 13, 2025
    risk 0.64cvss 9.8epss 0.01

    Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive according boost library. The version of boost library contains vulnerability integer overflow.