VYPR

CVEs

38,065 total · page 257 of 762

  • CVE-2025-24370CriFeb 3, 2025
    risk 0.53cvss —epss 0.00

    Django-Unicorn adds modern reactive component functionality to Django templates. Affected versions of Django-Unicorn are vulnerable to python class pollution vulnerability. The vulnerability arises from the core functionality `set_property_value`, which can be remotely triggered…

  • CVE-2025-22978CriFeb 3, 2025
    risk 0.00cvss 9.8epss 0.01

    eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.

  • CVE-2024-57968CriKEVFeb 3, 2025
    risk 0.79cvss 9.9epss 0.32

    Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.

  • CVE-2024-57450CriFeb 3, 2025
    risk 0.64cvss 9.8epss 0.01

    ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function.

  • CVE-2024-57099CriFeb 3, 2025
    risk 0.64cvss 9.8epss 0.01

    ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, allowing them to execute arbitrary code and potentially take control of the server.

  • CVE-2024-57098CriFeb 3, 2025
    risk 0.64cvss 9.8epss 0.00

    Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into the order parameter.

  • CVE-2024-45569CriFeb 3, 2025
    risk 0.64cvss 9.8epss 0.01

    Memory corruption while parsing the ML IE due to invalid frame content.

  • CVE-2025-20634CriFeb 3, 2025
    risk 0.64cvss 9.8epss 0.01

    In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2025-24891CriJan 31, 2025
    risk 0.55cvss 9.6epss 0.01

    Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traversal vulnerability to overwrite arbitrary system files. As the container runs as root by default, there is no limit to what can be overwritten. With this, it's…

  • CVE-2024-57587CriJan 31, 2025
    risk 0.59cvss 9.1epss 0.01

    Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to /api/auth/login.

  • CVE-2024-55062CriJan 31, 2025
    risk 0.64cvss 9.8epss 0.01

    Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary code to /api/license/sendlicense/.

  • CVE-2024-53356CriJan 31, 2025
    risk 0.64cvss 9.8epss 0.01

    Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. The HMAC secret used for generating tokens is hardcoded as "somerandomaccesstoken". A weak HMAC secret poses a risk because…

  • CVE-2025-22957CriJan 31, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could potentially allow attackers to gain unauthorized access to the database and extract sensitive information.

  • CVE-2024-53584CriJan 31, 2025
    risk 0.67cvss 9.8epss 0.04

    OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.

  • CVE-2024-47857CriJan 31, 2025
    risk 0.64cvss 9.8epss 0.00

    SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures when using native SSH connections via a proxy port. This allows an existing PrivX "account A" to impersonate another existing PrivX "account B" and gain access…

  • CVE-2025-23215CriJan 31, 2025
    risk 0.53cvss —epss 0.00

    PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing keys are included in jar published to Maven Central. The private key itself is not known to have been compromised itself, but given its passphrase is, it must…

  • CVE-2024-53537CriJan 31, 2025
    risk 0.62cvss 9.1epss 0.02

    An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager.

  • CVE-2024-53320CriJan 31, 2025
    risk 0.64cvss 9.8epss 0.00

    Qualisys C++ SDK commit a32a21a was discovered to contain multiple stack buffer overflows via the GetCurrentFrame, SaveCapture, and LoadProject functions.

  • CVE-2025-0929CriJan 31, 2025
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in TeamCal Neo, version 3.8.2. This could allow an attacker to retrieve, update and delete all database information by injecting a malicious SQL statement via the ‘abs’ parameter in ‘/teamcal/src/index.php’.

  • CVE-2025-21673CriJan 31, 2025
    risk 0.64cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double free of TCP_Server_Info::hostname When shutting down the server in cifs_put_tcp_session(), cifsd thread might be reconnecting to multiple DFS targets before it realizes it should exit…

  • CVE-2025-0493CriJan 31, 2025
    risk 0.64cvss 9.8epss 0.01

    The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limited Local File Inclusion in all versions up to, and including, 4.2.14 via the tabname parameter. This makes it possible for unauthenticated attackers to…

  • CVE-2022-1736CriJan 31, 2025
    risk 0.64cvss 9.8epss 0.01

    Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.

  • CVE-2025-24503CriJan 30, 2025
    risk 0.60cvss —epss 0.00

    A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.

  • CVE-2025-0680CriJan 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected to the cloud.

  • CVE-2024-12248CriJan 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution.

  • CVE-2025-0498CriJan 30, 2025
    risk 0.64cvss 9.8epss 0.00

    A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate…

  • CVE-2025-0497CriJan 30, 2025
    risk 0.64cvss 9.8epss 0.00

    A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or…

  • CVE-2025-0477CriJan 30, 2025
    risk 0.64cvss 9.8epss 0.00

    An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.

  • CVE-2024-13742CriJan 30, 2025
    risk 0.64cvss 9.8epss 0.01

    The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.5 via deserialization of untrusted input from the reqpars parameter. This makes it possible for unauthenticated attackers to…

  • CVE-2024-12822CriJan 30, 2025
    risk 0.64cvss 9.8epss 0.01

    The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the add_capto_img() function in all versions up to, and including, 3.11.0. This makes it possible for…

  • CVE-2025-21415CriJan 29, 2025
    risk 0.64cvss 9.9epss 0.01

    Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.

  • CVE-2024-57665CriJan 29, 2025
    risk 0.64cvss 9.8epss 0.01

    JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability is that the title parameter is controllable and is concatenated directly into filterSql without filtering.

  • CVE-2025-0851CriJan 29, 2025
    risk 0.59cvss 9.8epss 0.23

    A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary locations.

  • CVE-2024-57395CriJan 29, 2025
    risk 0.64cvss 9.8epss 0.01

    Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbitrary code and obtain sensitive information via the password and account number parameters.

  • CVE-2024-54852CriJan 29, 2025
    risk 0.64cvss 9.8epss 0.01

    When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as…

  • CVE-2025-20061CriJan 29, 2025
    risk 0.64cvss 9.8epss 0.01

    mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.

  • CVE-2025-20014CriJan 29, 2025
    risk 0.64cvss 9.8epss 0.01

    mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.

  • CVE-2024-48852CriJan 29, 2025
    risk 0.64cvss 9.4epss 0.02

    Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access. This issue affects FLXEON through <= 9.3.4.

  • CVE-2024-48849CriJan 29, 2025
    risk 0.64cvss 9.4epss 0.01

    Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= 9.3.4.

  • CVE-2025-24480CriJan 28, 2025
    risk 0.61cvss —epss 0.01

    A Remote Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to lack of input sanitation and could allow a remote attacker to run commands or code as a high privileged user.

  • CVE-2025-24800CriJan 28, 2025
    risk 0.53cvss —epss 0.00

    Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability. A critical vulnerability was discovered in the ismp-grandpa crate, that allowed a malicious prover easily convince the verifier of the finality of arbitrary headers. This could be used to…

  • CVE-2025-23211CriJan 28, 2025
    risk 0.00cvss 9.9epss 0.04

    Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. In the case of the provided Docker Compose file as root. This vulnerability is fixed in 1.5.24.

  • CVE-2025-23045CriJan 28, 2025
    risk 0.00cvss 9.8epss 0.01

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affected CVAT instance is able to run arbitrary code in the context of the Nuclio function container. This vulnerability affects CVAT…

  • CVE-2024-13448CriJan 28, 2025
    risk 0.64cvss 9.8epss 0.01

    The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_data' function in all versions up to, and including, 2.32.3. This makes it possible for unauthenticated attackers to upload…

  • CVE-2024-12649CriJan 28, 2025
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw…

  • CVE-2024-12648CriJan 28, 2025
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in TIFF data EXIF tag processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw…

  • CVE-2024-12647CriJan 28, 2025
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw…

  • CVE-2022-3365CriJan 28, 2025
    risk 0.67cvss 9.8epss 0.02

    Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be abused by attackers to inject OS commands over theproduct's custom control…

  • CVE-2024-57548CriJan 27, 2025
    risk 0.59cvss 9.1epss 0.00

    CMSimple 5.16 allows the user to edit log.php file via print page.

  • CVE-2024-57052CriJan 27, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file.