VYPR

CVEs

31,889 total · page 255 of 638

  • CVE-2025-9172HigAug 26, 2025
    risk 0.49cvss 7.5epss 0.00

    The Vibes plugin for WordPress is vulnerable to time-based SQL Injection via the ‘resource’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

  • CVE-2025-9444HigAug 26, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in 1000projects Online Project Report Submission and Evaluation System 1.0. This issue affects some unknown processing of the file /admin/controller/delete_group_student.php. The manipulation of the argument batch_id leads to sql injection. The…

  • CVE-2025-9426HigAug 25, 2025
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of the file /package.php. Executing manipulation of the argument subcatid can lead to sql injection. The attack may be performed from a remote location. The…

  • CVE-2025-9425HigAug 25, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in itsourcecode Online Tour and Travel Management System 1.0. Affected by this issue is some unknown functionality of the file /enquiry.php. Performing manipulation of the argument pid results in sql injection. The attack is possible to be…

  • CVE-2025-9423HigAug 25, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in Campcodes Online Water Billing System 1.0. Affected is an unknown function of the file /editecex.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly…

  • CVE-2025-9421HigAug 25, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in itsourcecode Apartment Management System 1.0. This affects an unknown function of the file /complain/addcomplain.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-9420HigAug 25, 2025
    risk 0.47cvss 7.3epss 0.01

    A flaw has been found in itsourcecode Apartment Management System 1.0. The impacted element is an unknown function of the file /floor/addfloor.php. Executing manipulation of the argument hdnid can lead to sql injection. The attack can be launched remotely. The exploit has been…

  • CVE-2025-57805HigAug 25, 2025
    risk 0.50cvss epss 0.00

    The Scratch Channel is a news website. In versions 1 and 1.1, a POST request to the endpoint used to publish articles, can be used to post an article in any category with any date, regardless of who's logged in. This issue has been patched in version 1.2.

  • CVE-2025-9419HigAug 25, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was detected in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /unit/addunit.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now…

  • CVE-2025-9418HigAug 25, 2025
    risk 0.47cvss 7.3epss 0.01

    A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /owner/addowner.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has…

  • CVE-2025-6188HigAug 25, 2025
    risk 0.49cvss 7.5epss 0.00

    On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. UDP Port 3503 is associated with LspPing Echo Reply. This can result in unexpected behaviors, especially for UDP based services that do not perform some form of…

  • CVE-2025-57802HigAug 25, 2025
    risk 0.50cvss epss 0.00

    Airlink's Daemon interfaces with Docker and the Panel to provide secure access for controlling instances via the Panel. In version 1.0.0, an attacker with access to the affected container can create symbolic links inside the mounted directory (/app/data). Because the container…

  • CVE-2025-6737HigAug 25, 2025
    risk 0.47cvss 7.2epss 0.00

    Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenants. A malicious actor can obtain authentication material and access the gateway server with low-privilege permissions.

  • CVE-2025-53119HigAug 25, 2025
    risk 0.49cvss 7.5epss 0.11

    An unauthenticated unrestricted file upload vulnerability allows an attacker to upload malicious binaries and scripts to the server.

  • CVE-2025-3478HigAug 25, 2025
    risk 0.55cvss epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited.

  • CVE-2025-5302HigAug 25, 2025
    risk 0.49cvss 8.6epss 0.00

    A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifically in version v0.12.37. The vulnerability is caused by uncontrolled recursion when parsing deeply nested JSON files, which can lead to Python hitting its…

  • CVE-2025-56216HigAug 25, 2025
    risk 0.55cvss 8.5epss 0.00

    phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter.

  • CVE-2025-54370HigAug 25, 2025
    risk 0.50cvss epss 0.01

    PhpOffice/PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to versions 1.30.0, 2.1.12, 2.4.0, 3.10.0, and 5.0.0, SSRF can occur when a processed HTML document is read and displayed in the browser. The vulnerability lies in the setPath method…

  • CVE-2025-5191HigAug 25, 2025
    risk 0.47cvss epss 0.00

    An Unquoted Search Path vulnerability has been identified in the utility for Moxa’s industrial computers (Windows). Due to the unquoted path configuration in the SerialInterfaceService.exe utility, a local attacker with limited privileges could place a malicious executable in…

  • CVE-2025-54301HigAug 25, 2025
    risk 0.55cvss epss 0.00

    A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. File names are not properly escaped.

  • CVE-2025-54300HigAug 25, 2025
    risk 0.55cvss epss 0.00

    A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. The SVG upload feature does not sanitize uploads.

  • CVE-2025-9380HigAug 24, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was identified in FNKvision Y215 CCTV Camera 10.194.120.40. Affected by this issue is some unknown functionality of the file /etc/passwd of the component Firmware. Such manipulation leads to hard-coded credentials. Local access is required to approach this…

  • CVE-2025-9379HigAug 24, 2025
    risk 0.47cvss 7.2epss 0.00

    A vulnerability was determined in Belkin AX1800 1.1.00.016. Affected by this vulnerability is an unknown functionality of the component Firmware Update Handler. This manipulation causes insufficient verification of data authenticity. The attack can be initiated remotely. The…

  • CVE-2025-5060HigAug 23, 2025
    risk 0.53cvss 8.1epss 0.00

    The Bravis User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly logging a user in with the data that was previously verified through the facebook_ajax_login_callback(). This makes it…

  • CVE-2025-7813HigAug 23, 2025
    risk 0.40cvss 7.2epss 0.00

    The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxy_image function. This makes it possible for unauthenticated attackers to…

  • CVE-2025-9048HigAug 23, 2025
    risk 0.53cvss 8.1epss 0.01

    The Wptobe-memberships plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the del_img_ajax_call() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with…

  • CVE-2025-57771HigAug 22, 2025
    risk 0.46cvss 8.1epss 0.01

    Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions prior to 3.25.5, Roo-Code fails to properly handle process substitution and single ampersand characters in the command parsing logic for auto-execute commands. If a user has enabled…

  • CVE-2024-53494HigAug 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive components without authentication.

  • CVE-2025-38670HigAug 22, 2025
    risk 0.46cvss 7.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: arm64/entry: Mask DAIF in cpu_switch_to(), call_on_irq_stack() `cpu_switch_to()` and `call_on_irq_stack()` manipulate SP to change to different stacks along with the Shadow Call Stack if it is enabled. Those…

  • CVE-2025-38627HigAug 22, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix UAF of f2fs_inode_info in f2fs_free_dic The decompress_io_ctx may be released asynchronously after I/O completion. If this file is deleted immediately after read, and the kworker of…

  • CVE-2024-56179HigAug 22, 2025
    risk 0.51cvss 7.8epss 0.00

    In MindManager Windows versions prior to 24.1.150, attackers could potentially write to unexpected directories in victims' machines via directory traversal if victims opened file attachments located in malicious mmap files.

  • CVE-2025-41451HigAug 22, 2025
    risk 0.57cvss epss 0.01

    Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfoss AK-SM8xxA Series prior to version 4.3.1, leading to a potential post-authenticated remote code execution on an attacked system.

  • CVE-2025-51606HigAug 21, 2025
    risk 0.57cvss 8.8epss 0.00

    hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with access to the source code or compiled binary to forge valid access tokens and impersonate any user, including privileged ones such as "admin". The vulnerability…

  • CVE-2010-20123HigAug 21, 2025
    risk 0.58cvss epss 0.00

    Steinberg MyMP3Player version 3.0 (build 3.0.0.67) is vulnerable to a stack-based buffer overflow when parsing .m3u playlist files. The application fails to properly validate the length of input data within the playlist, allowing a specially crafted file to overwrite critical…

  • CVE-2010-20120HigAug 21, 2025
    risk 0.58cvss epss 0.00

    Maple versions up to and including 13's Maplet framework allows embedded commands to be executed automatically when a .maplet file is opened. This behavior bypasses standard security restrictions that normally prevent code execution in regular Maple worksheets. The vulnerability…

  • CVE-2010-20114HigAug 21, 2025
    risk 0.58cvss epss 0.00

    VariCAD EN up to and including version 2010-2.05 is vulnerable to a stack-based buffer overflow when parsing .dwb drawing files. The application fails to properly validate the length of input data embedded in the file, allowing a crafted .dwb file to overwrite critical memory…

  • CVE-2010-20108HigAug 21, 2025
    risk 0.59cvss epss 0.00

    FTPPad <= 1.2.0 contains a stack-based buffer overflow vulnerability in its FTP directory listing parser. When the client connects to an FTP server and receives a crafted response to a LIST command containing an excessively long directory and filename, the application fails to…

  • CVE-2010-20107HigAug 21, 2025
    risk 0.60cvss epss 0.00

    A stack-based buffer overflow exists in FTP Synchronizer Professional <= v4.0.73.274. When the client connects to an FTP server and issues a LIST command—typically during sync preview or profile creation—the server’s response containing an overly long filename triggers a…

  • CVE-2010-20034HigAug 21, 2025
    risk 0.60cvss epss 0.00

    Gekko Manager FTP Client <= 0.77 contains a stack-based buffer overflow in its FTP directory listing parser. When processing a server response to a LIST command, the client fails to properly validate the length of filenames. A crafted response containing an overly long filename…

  • CVE-2010-20007HigAug 21, 2025
    risk 0.60cvss epss 0.00

    Seagull FTP Client <= v3.3 Build 409 contains a stack-based buffer overflow vulnerability in its FTP directory listing parser. When the client connects to an FTP server and receives a crafted response to a LIST command containing an excessively long filename, the application…

  • CVE-2009-20004HigAug 21, 2025
    risk 0.58cvss epss 0.00

    gAlan 0.2.1, a modular audio processing environment for Windows, is vulnerable to a stack-based buffer overflow when parsing .galan files. The application fails to properly validate the length of input data, allowing a specially crafted file to overwrite the stack and execute…

  • CVE-2009-20003HigAug 21, 2025
    risk 0.58cvss epss 0.00

    Xenorate versions up to and including 2.50, a Windows-based multimedia player, is vulnerable to a stack-based buffer overflow when processing .xpl playlist files. The application fails to properly validate the length of input data, allowing an attacker to craft a malicious .xpl…

  • CVE-2009-20002HigAug 21, 2025
    risk 0.60cvss epss 0.00

    Millenium MP3 Studio versions up to and including 2.0 is vulnerable to a stack-based buffer overflow when parsing .pls playlist files. The application fails to properly validate the length of the File1 field within the playlist, allowing an attacker to craft a malicious .pls…

  • CVE-2025-54460HigAug 21, 2025
    risk 0.46cvss 7.1epss 0.00

    The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to create or access publication targets of type Text File or HDFS) to upload and persist files that could potentially be executed.

  • CVE-2025-51989HigAug 21, 2025
    risk 0.46cvss 7.0epss 0.00

    HTML injection vulnerability in the registration interface in Evolution Consulting Kft. HRmaster module v235 allows an attacker to inject HTML tags into the "keresztnév" (firstname) field, which will be sent out in an email resulting in possible Phishing scenarios against any,…

  • CVE-2025-27721HigAug 21, 2025
    risk 0.49cvss 7.5epss 0.00

    Unauthorized users can access INFINITT PACS System Manager without proper authorization, which could lead to unauthorized access to system resources.

  • CVE-2010-20119HigAug 21, 2025
    risk 0.63cvss epss 0.01

    CommuniCrypt Mail versions up to and including 1.16 contains a stack-based buffer overflow vulnerability in its ANSMTP.dll and AOSMTP.dll ActiveX controls, specifically within the AddAttachments() method. This method fails to properly validate the length of input strings,…

  • CVE-2010-20111HigAug 21, 2025
    risk 0.58cvss epss 0.00

    Digital Music Pad v8.2.3.3.4 contains a stack-based buffer overflow vulnerability in its playlist file parser. When opening a .pls file containing an excessively long string in the File1 field, the application fails to properly validate input length, resulting in corruption of…

  • CVE-2010-20109HigAug 21, 2025
    risk 0.64cvss epss 0.01

    Barracuda products, confirmed in Spam & Virus Firewall, SSL VPN, and Web Application Firewall versions prior to October 2010, contain a path traversal vulnerability in the view_help.cgi endpoint. The locale parameter fails to properly sanitize user input, allowing attackers to…

  • CVE-2010-10015HigAug 21, 2025
    risk 0.60cvss epss 0.00

    AOL versions up to and including 9.5 includes an ActiveX control (Phobos.dll) that exposes a method called Import() via the Phobos.Playlist COM object. This method is vulnerable to a stack-based buffer overflow when provided with an excessively long string argument. Exploitation…