VYPR

CVEs

38,065 total · page 255 of 762

  • CVE-2025-1127CriFeb 13, 2025
    risk 0.59cvss 9.1epss 0.01

    The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user and/or modify the contents of any data on the filesystem.

  • CVE-2025-25389CriFeb 13, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /admin/forgot-password.php in Phpgurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactno POST request parameter.

  • CVE-2025-25388CriFeb 13, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /admin/edit-propertytype.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the editid GET request parameter.

  • CVE-2025-1270CriFeb 13, 2025
    risk 0.59cvss 9.1epss 0.00

    Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access other users' information by making a POST request and modifying the “pkrelated” parameter in the “/h6web/ha_datos_hermano.php” endpoint to refer to…

  • CVE-2024-13182CriFeb 13, 2025
    risk 0.64cvss 9.8epss 0.01

    The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_parse_request' function. This makes it possible for unauthenticated attackers to log in as any…

  • CVE-2024-10763CriFeb 13, 2025
    risk 0.64cvss 9.8epss 0.04

    The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_ajax_products' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server,…

  • CVE-2025-0896CriFeb 13, 2025
    risk 0.64cvss 9.8epss 0.02

    Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by an attacker.

  • CVE-2025-25286CriFeb 13, 2025
    risk 0.57cvss 9.8epss 0.01

    Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, provides FFmpeg as a microservice. Prior to Crayfish version 4.1.0, remote code execution may be possible in web-accessible installations of Homarus in certain configurations. The issue has been…

  • CVE-2024-7102CriFeb 13, 2025
    risk 0.62cvss 9.6epss 0.01

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances.

  • CVE-2024-57604CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.

  • CVE-2024-57602CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.

  • CVE-2022-31631CriFeb 12, 2025
    risk 0.59cvss 9.1epss 0.02

    In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection…

  • CVE-2025-0108CriKEVFeb 12, 2025
    risk 0.79cvss 9.1epss 0.98

    An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While…

  • CVE-2025-25343CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.

  • CVE-2025-25746CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetWanSettings module.

  • CVE-2025-25744CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetDynamicDNSSettings module.

  • CVE-2025-25742CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the AccountPassword parameter in the SetSysEmailSettings module.

  • CVE-2025-25182CriFeb 12, 2025
    risk 0.54cvss 9.4epss 0.01

    Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and prior to versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2 that allows authentication bypass to a Stroom system when configured with ALB and installed in a…

  • CVE-2025-25351CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense parameter.

  • CVE-2025-25349CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem parameter.

  • CVE-2025-26361CriFeb 12, 2025
    risk 0.59cvss 9.1epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to factory reset the device via crafted HTTP requests.

  • CVE-2025-26359CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to reset user PINs via crafted HTTP requests.

  • CVE-2025-26347CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to edit user permissions via crafted HTTP requests.

  • CVE-2025-26345CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to edit user group permissions via crafted HTTP requests.

  • CVE-2025-26344CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/guest-mode/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable passwordless guest mode via crafted HTTP requests.

  • CVE-2025-26342CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to create arbitrary users, including administrators, via crafted HTTP requests.

  • CVE-2025-26341CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to reset arbitrary user passwords via crafted HTTP requests.

  • CVE-2025-26339CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to affect the device confidentiality, integrity, or availability in multiple unspecified ways via…

  • CVE-2025-1100CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to execute arbitrary code with root privileges via SSH.

  • CVE-2024-10960CriFeb 12, 2025
    risk 0.57cvss 9.9epss 0.01

    The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' function in all versions up to, and including, 2.6.4. This makes it possible for authenticated attackers, with Contributor-level…

  • CVE-2024-13365CriFeb 12, 2025
    risk 0.57cvss 9.8epss 0.02

    The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149.…

  • CVE-2024-12213CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an…

  • CVE-2024-13421CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated…

  • CVE-2022-3180CriFeb 11, 2025
    risk 0.64cvss 9.8epss 0.09

    The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.

  • CVE-2025-25530CriFeb 11, 2025
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow vulnerability in Digital China DCBI-Netlog-LAB Gateway 1.0 due to the lack of length verification, which is related to saving parental control configuration information. Attackers who successfully exploit this vulnerability can cause the remote target device to…

  • CVE-2025-1044CriFeb 11, 2025
    risk 0.70cvss 9.8epss 0.75

    Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw…

  • CVE-2025-24434CriFeb 11, 2025
    risk 0.60cvss 9.1epss 0.17

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain…

  • CVE-2025-21198CriFeb 11, 2025
    risk 0.59cvss 9.0epss 0.01

    Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability

  • CVE-2025-1126CriFeb 11, 2025
    risk 0.60cvss 9.3epss 0.00

    A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client.

  • CVE-2025-24973CriFeb 11, 2025
    risk 0.53cvss 9.3epss 0.00

    Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1, due to an improper implementation of the logout process, authentication credentials remain in cookies even after a user has explicitly logged out, which may…

  • CVE-2025-22467CriFeb 11, 2025
    risk 0.65cvss 9.9epss 0.05

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.

  • CVE-2024-47908CriFeb 11, 2025
    risk 0.61cvss 9.1epss 0.22

    OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-10644CriFeb 11, 2025
    risk 0.59cvss 9.1epss 0.03

    Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-12366CriFeb 11, 2025
    risk 0.64cvss 9.8epss 0.01

    PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM.

  • CVE-2025-26410CriFeb 11, 2025
    risk 0.64cvss 9.8epss 0.01

    The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via the login shell that is exposed by the…

  • CVE-2025-0181CriFeb 11, 2025
    risk 0.64cvss 9.8epss 0.01

    The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.8. This is due to the plugin not properly validating a user's identity prior to setting the current user and their authentication cookie.…

  • CVE-2025-0180CriFeb 11, 2025
    risk 0.64cvss 9.8epss 0.01

    The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible for unauthenticated…

  • CVE-2025-1144CriFeb 11, 2025
    risk 0.64cvss 9.8epss 0.01

    School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing unauthenticated attackers to view specific pages and obtain database information as well as plaintext administrator credentials.

  • CVE-2025-24016CriKEVFeb 10, 2025
    risk 0.87cvss 9.9epss 0.94

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI parameters are a…

  • CVE-2024-13011CriFeb 10, 2025
    risk 0.64cvss 9.8epss 0.01

    The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_profile_image' function in versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to upload…