VYPR

CVEs

31,891 total · page 262 of 638

  • CVE-2025-8952HigAug 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Campcodes Online Flight Booking Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Login. The manipulation of the argument Username leads to sql injection. The…

  • CVE-2025-48862HigAug 14, 2025
    risk 0.46cvss 7.1epss 0.00

    Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup file is encrypted when a password is set. However, only the private key - if available in the backup - is encrypted, while the backup file itself remains…

  • CVE-2025-48860HigAug 14, 2025
    risk 0.52cvss 8.0epss 0.00

    A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) attacker to gain remote access to backup archives created by a user with elevated permissions. Depending on the content of the backup archive, the attacker may…

  • CVE-2025-8951HigAug 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in PHPGurukul Teachers Record Management System 2.1. Affected is an unknown function of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has…

  • CVE-2025-8950HigAug 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in Campcodes Online Recruitment Management System 1.0. This issue affects some unknown processing of the file /Recruitment/index.php?page=view_vacancy. The manipulation of the argument ID leads to sql injection. The attack may be initiated…

  • CVE-2025-27388HigAug 14, 2025
    risk 0.54cvss epss 0.00

    Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.

  • CVE-2025-8948HigAug 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in projectworlds Visitor Management System 1.0. Affected is an unknown function of the file /front.php. The manipulation of the argument rid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…

  • CVE-2025-8947HigAug 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in projectworlds Visitor Management System 1.0. This issue affects some unknown processing of the file /query_data.php. The manipulation of the argument dateF/dateP leads to sql injection. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-8946HigAug 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in projectworlds Online Notes Sharing Platform 1.0. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument User leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…

  • CVE-2025-8936HigAug 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in 1000 Projects Sales Management System 1.0. Affected by this issue is some unknown functionality of the file /superstore/dist/dordupdate.php. The manipulation of the argument select2 leads to sql injection. The attack may be launched remotely.…

  • CVE-2024-7402HigAug 14, 2025
    risk 0.46cvss epss 0.00

    Netskope has identified a potential gap in its agent (Netskope Client) in which a malicious insider can potentially tamper the Netskope Client configuration by performing MITM (Man-in-the-Middle) activity on the Netskope Client communication channel. A successful exploitation…

  • CVE-2025-8935HigAug 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in 1000 Projects Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /superstore/custcmp.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The…

  • CVE-2025-8932HigAug 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in 1000 Projects Sales Management System 1.0. This vulnerability affects unknown code of the file /superstore/admin/sales.php. The manipulation of the argument ssalescat leads to sql injection. The attack can be initiated remotely. The exploit has…

  • CVE-2025-55196HigAug 13, 2025
    risk 0.39cvss epss 0.00

    External Secrets Operator is a Kubernetes operator that integrates external secret management systems. From version 0.15.0 to before 0.19.2, a vulnerability was discovered where the List() calls for Kubernetes Secret and SecretStore resources performed by the PushSecret…

  • CVE-2012-10057HigAug 13, 2025
    risk 0.58cvss epss 0.00

    Lattice Semiconductor ispVM System v18.0.2 contains a buffer overflow vulnerability in its handling of .xcf project files. When parsing the version attribute of the ispXCF XML tag, the application fails to properly validate input length, allowing a specially crafted file to…

  • CVE-2012-10056HigAug 13, 2025
    risk 0.64cvss epss 0.01

    PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnerability in its document upload functionality. Authenticated users can upload files to the mods/documents/uploads/ directory without any restriction on file type or extension. Because this directory is…

  • CVE-2011-10014HigAug 13, 2025
    risk 0.60cvss epss 0.00

    GTA San Andreas Multiplayer (SA-MP) server version 0.3.1.1 is vulnerable to a stack-based buffer overflow triggered by parsing a malformed server.cfg configuration file. The vulnerability allows local attackers to execute arbitrary code when the server binary (samp-server.exe)…

  • CVE-2011-10012HigAug 13, 2025
    risk 0.59cvss epss 0.00

    NetOp (now part of Impero Software) Remote Control Client v9.5 is vulnerable to a stack-based buffer overflow when processing .dws configuration files. If a .dws file contains a string longer than 520 bytes, the application fails to perform proper bounds checking, allowing an…

  • CVE-2011-10009HigAug 13, 2025
    risk 0.65cvss epss 0.02

    S40 CMS v0.4.2 contains a path traversal vulnerability in its index.php page handler. The p parameter is not properly sanitized, allowing attackers to traverse the file system and access arbitrary files outside the web root. This can be exploited remotely without authentication…

  • CVE-2025-8926HigAug 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in SourceCodester COVID 19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The…

  • CVE-2025-43988HigAug 13, 2025
    risk 0.49cvss 7.5epss 0.00

    KuWFi 5G01-X55 FL2020_V0.0.12 devices expose an unauthenticated API endpoint (ajax_get.cgi), allowing remote attackers to retrieve sensitive configuration data, including admin credentials.

  • CVE-2025-8925HigAug 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in itsourcecode Sports Management System 1.0. Affected is an unknown function of the file /Admin/match.php. The manipulation of the argument code leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed…

  • CVE-2025-8924HigAug 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in Campcodes Online Water Billing System 1.0. This issue affects some unknown processing of the file /viewbill.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to…

  • CVE-2025-8923HigAug 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in code-projects Job Diary 1.0. This vulnerability affects unknown code of the file /edit-details.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public…

  • CVE-2025-8922HigAug 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Job Diary 1.0. This affects an unknown part of the file /admin-inbox.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may…

  • CVE-2025-8921HigAug 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in code-projects Job Diary 1.0. Affected by this issue is some unknown functionality of the file /user-apply.php. The manipulation of the argument job_title leads to sql injection. The attack may be launched remotely. The exploit has been disclosed…

  • CVE-2025-8904HigAug 13, 2025
    risk 0.55cvss 8.5epss 0.00

    Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account can potentially decrypt the keys and escalate to higher privileges. Users are advised to…

  • CVE-2025-8754HigAug 13, 2025
    risk 0.49cvss 7.5epss 0.00

    Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM zenon: from 7.50 through 14.

  • CVE-2025-23298HigAug 13, 2025
    risk 0.51cvss 7.8epss 0.01

    NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability in a python dependency, where an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and…

  • CVE-2025-23296HigAug 13, 2025
    risk 0.51cvss 7.8epss 0.01

    NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component where an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

  • CVE-2025-23294HigAug 13, 2025
    risk 0.51cvss 7.8epss 0.00

    NVIDIA WebDataset for all platforms contains a vulnerability where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.

  • CVE-2024-5477HigAug 13, 2025
    risk 0.47cvss epss 0.00

    A potential security vulnerability has been identified in the System BIOS for some HP PC products which may allow escalation of privilege, arbitrary code execution, denial of service, or information disclosure via a physical attack that requires specialized equipment and…

  • CVE-2025-8941HigAug 13, 2025
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.

  • CVE-2025-8907HigAug 13, 2025
    risk 0.46cvss 7.0epss 0.00

    A vulnerability was found in H3C M2 NAS V100R006. Affected by this vulnerability is an unknown functionality of the component Webserver Configuration. The manipulation leads to execution with unnecessary privileges. An attack has to be approached locally. The complexity of an…

  • CVE-2025-8671HigAug 13, 2025
    risk 0.49cvss 7.5epss 0.05

    A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then…

  • CVE-2025-48989HigAug 13, 2025
    risk 0.42cvss 7.5epss 0.03

    Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may…

  • CVE-2025-54464HigAug 13, 2025
    risk 0.46cvss epss 0.00

    This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the…

  • CVE-2025-55345HigAug 13, 2025
    risk 0.57cvss 8.8epss 0.01

    Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code execution due to symlinks being followed outside the allowed current working directory.

  • CVE-2025-8761HigAug 13, 2025
    risk 0.49cvss 7.5epss 0.06

    A vulnerability has been found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This vulnerability affects unknown code of the component Backend IPC Server. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and…

  • CVE-2025-6184HigAug 13, 2025
    risk 0.57cvss 8.8epss 0.00

    The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter used in the get_submitted_assignments() function in all versions up to, and including, 3.7.0 due to insufficient escaping on…

  • CVE-2025-4410HigAug 13, 2025
    risk 0.49cvss 7.5epss 0.00

    A buffer overflow vulnerability exists in the module SetupUtility. An attacker with local privileged access can exploit this vulnerability by executeing arbitrary code.

  • CVE-2025-4277HigAug 13, 2025
    risk 0.49cvss 7.5epss 0.00

    Tcg2Smm has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.

  • CVE-2025-4276HigAug 13, 2025
    risk 0.49cvss 7.5epss 0.00

    UsbCoreDxe has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.

  • CVE-2025-55165HigAug 12, 2025
    risk 0.46cvss 8.2epss 0.00

    Autocaliweb is a web app that offers an interface for browsing, reading, and downloading eBooks using a valid Calibre database. Prior to version 0.8.3, the debug pack generated by Autocaliweb can expose sensitive configuration data, including API keys. This occurs because the…

  • CVE-2025-53744HigAug 12, 2025
    risk 0.47cvss 7.2epss 0.01

    An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escalate their…

  • CVE-2024-26009HigAug 12, 2025
    risk 0.53cvss 8.1epss 0.01

    An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, FortiProxy 7.4.0…

  • CVE-2025-53732HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-33051HigAug 12, 2025
    risk 0.49cvss 7.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-32086HigAug 12, 2025
    risk 0.47cvss 7.2epss 0.00

    Improperly implemented security check for standard in the DDRIO configuration for some Intel(R) Xeon(R) 6 Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2025-26403HigAug 12, 2025
    risk 0.47cvss 7.2epss 0.00

    Out-of-bounds write in the memory subsystem for some Intel(R) Xeon(R) 6 processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.