VYPR

CVEs

38,009 total · page 286 of 761

  • CVE-2025-22239HigJun 13, 2025
    risk 0.46cvss 8.1epss 0.00

    Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event bus.

  • CVE-2025-22236HigJun 13, 2025
    risk 0.53cvss 8.1epss 0.00

    Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).

  • CVE-2025-5491HigJun 13, 2025
    risk 0.57cvss 8.8epss 0.01

    Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing remote users with low privileges to interact with it and access…

  • CVE-2025-4230HigJun 13, 2025
    risk 0.55cvss epss 0.01

    A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI. The security…

  • CVE-2025-6031HigJun 12, 2025
    risk 0.49cvss 7.5epss 0.00

    Amazon Cloud Cam is a home security camera that was deprecated on December 2, 2022, is end of life, and is no longer actively supported. When a user powers on the Amazon Cloud Cam, the device attempts to connect to a remote service infrastructure that has been deprecated due…

  • CVE-2025-5485HigJun 12, 2025
    risk 0.56cvss 8.6epss 0.00

    User names used to access the web management interface are limited to the device identifier, which is a numerical identifier no more than 10 digits. A malicious actor can enumerate potential targets by incrementing or decrementing from known identifiers or through …

  • CVE-2025-5484HigJun 12, 2025
    risk 0.54cvss 8.3epss 0.00

    A username and password are required to authenticate to the central SinoTrack device management interface. The username for all devices is an identifier printed on the receiver. The default password is well-known and common to all devices. Modification of the default …

  • CVE-2025-44019HigJun 12, 2025
    risk 0.46cvss 7.1epss 0.00

    AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting in a denial of service. Depending on the timing of the crash, data present in…

  • CVE-2024-7562HigJun 12, 2025
    risk 0.47cvss epss 0.00

    A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple InstallScript custom actions configured. All supported versions (InstallShield 2023 R2, InstallShield 2022 R2 and InstallShield 2021 R2) are affected by this…

  • CVE-2025-6021HigJun 12, 2025
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.

  • CVE-2025-35978HigJun 12, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary registry value may be modified or…

  • CVE-2025-32465HigJun 11, 2025
    risk 0.55cvss epss 0.00

    A stored XSS vulnerability in RSTickets! component 1.9.12 - 3.3.0 for Joomla was discovered. It allows attackers to perform cross-site scripting (XSS) attacks via sending crafted payload.

  • CVE-2025-6002HigJun 11, 2025
    risk 0.47cvss 7.2epss 0.01

    An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable or malicious files, potentially leading to remote code execution or other security…

  • CVE-2025-6001HigJun 11, 2025
    risk 0.54cvss 8.3epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacker is able to craft a special CSRF request which will allow unrestricted file upload into the VirtueMart media manager.

  • CVE-2025-40915HigJun 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. That version of the module generates tokens as an MD5 of the process id, the current time, and a single call to the built-in rand() function.

  • CVE-2025-22874HigJun 11, 2025
    risk 0.42cvss 7.5epss 0.00

    Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

  • CVE-2025-49148HigJun 11, 2025
    risk 0.40cvss 7.3epss 0.00

    ClipShare is a lightweight and cross-platform tool for clipboard sharing. Prior to 3.8.5, ClipShare Server for Windows uses the default Windows DLL search order and loads system libraries like CRYPTBASE.dll and WindowsCodecs.dll from its own directory before the system path. A…

  • CVE-2025-5687HigJun 11, 2025
    risk 0.44cvss 7.8epss 0.00

    A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects Mozilla VPN on macOS. Other operating systems are unaffected.*. This vulnerability was fixed in Mozilla VPN 2.28.0 (macOS).

  • CVE-2025-3302HigJun 11, 2025
    risk 0.40cvss 7.2epss 0.00

    The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘HTTP_REFERER’ parameter in all versions up to, and including, 7.1.0.16 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2025-41661HigJun 11, 2025
    risk 0.57cvss 8.8epss 0.00

    An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of Cross-Site Request Forgery (CSRF) protection.

  • CVE-2025-29756HigJun 11, 2025
    risk 0.54cvss epss 0.00

    SunGrow's back end users system iSolarCloud https://isolarcloud.com  uses an MQTT service to transport data from the user's connected devices to the user's web browser.  The MQTT server however did not have sufficient restrictions in place to limit the topics that a user…

  • CVE-2025-5395HigJun 11, 2025
    risk 0.57cvss 8.8epss 0.01

    The WordPress Automatic Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'core.php' file in all versions up to, and including, 3.115.0. This makes it possible for authenticated attackers, with Author-level access…

  • CVE-2025-4275HigJun 11, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass…

  • CVE-2025-49091HigJun 11, 2025
    risk 0.53cvss 8.2epss 0.01

    KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed regardless of whether the ssh, telnet, or rlogin binary is available. In this…

  • CVE-2024-9062HigJun 11, 2025
    risk 0.51cvss 7.8epss 0.00

    The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its privileged helper tool, com.oct4pie.archifyhelper, which is exposed via XPC. Archify follows the "factored applications" model, delegating privileged…

  • CVE-2024-7457HigJun 11, 2025
    risk 0.51cvss 7.8epss 0.00

    The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of macOS’s authorization model. Instead of validating the client's authorization reference, the helper invokes AuthorizationCopyRights() using its own privileged context (root),…

  • CVE-2025-5985HigJun 10, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects School Fees Payment System 1.0 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper authentication. The attack may be launched remotely. The exploit has been disclosed to…

  • CVE-2025-5980HigJun 10, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical was found in code-projects Restaurant Order System 1.0. This vulnerability affects unknown code of the file /order.php. The manipulation of the argument tabidNoti leads to sql injection. The attack can be initiated remotely. The exploit has…

  • CVE-2025-5979HigJun 10, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical has been found in code-projects School Fees Payment System 1.0. This affects an unknown part of the file /branch.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit…

  • CVE-2025-35940HigJun 10, 2025
    risk 0.53cvss 8.1epss 0.00

    The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to access protected ArchiverSpaApi URL endpoints.

  • CVE-2025-5977HigJun 10, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects School Fees Payment System 1.0 and classified as critical. This issue affects some unknown processing of the file /datatable.php. The manipulation of the argument sSortDir_0 leads to sql injection. The attack may be initiated remotely.…

  • CVE-2025-3052HigJun 10, 2025
    risk 0.53cvss 8.2epss 0.00

    An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting…

  • CVE-2025-5943HigJun 10, 2025
    risk 0.57cvss 8.8epss 0.01

    MicroDicom DICOM Viewer suffers from an out-of-bounds write vulnerability. Remote attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of DICOM Viewer. User interaction is required to exploit the vulnerability in that the…

  • CVE-2025-0052HigJun 10, 2025
    risk 0.54cvss epss 0.00

    Improper input validation performed during the authentication process of FlashBlade could lead to a system Denial of Service.

  • CVE-2025-0051HigJun 10, 2025
    risk 0.57cvss epss 0.00

    Improper input validation performed during the authentication process of FlashArray could lead to a system Denial of Service.

  • CVE-2025-47953HigJun 10, 2025
    risk 0.55cvss 8.4epss 0.00

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-47167HigJun 10, 2025
    risk 0.55cvss 8.4epss 0.01

    Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-47164HigJun 10, 2025
    risk 0.55cvss 8.4epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-47162HigJun 10, 2025
    risk 0.55cvss 8.4epss 0.01

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2023-20599HigJun 10, 2025
    risk 0.51cvss 7.9epss 0.00

    Improper register access control in ASP may allow a privileged attacker to perform unauthorized access to ASP’s Crypto Co-Processor (CCP) registers from x86 resulting in potential loss of control of cryptographic key pointer/index leading to loss of integrity or…

  • CVE-2025-4678HigJun 10, 2025
    risk 0.46cvss epss 0.02

    Improper Neutralization of Special Elements in the chromium_path variable may allow OS command injection. This issue affects Pandora ITSM 5.0.105.

  • CVE-2025-4653HigJun 10, 2025
    risk 0.54cvss epss 0.02

    Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects Pandora ITSM 5.0.105.

  • CVE-2025-44044HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.00

    Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable SearchUnit host into parsing maliciously crafted XML and/or DTD files can exfiltrate some files from the underlying operating system.

  • CVE-2025-40591HigJun 10, 2025
    risk 0.50cvss 7.7epss 0.01

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5),…

  • CVE-2025-37100HigJun 10, 2025
    risk 0.50cvss 7.7epss 0.00

    A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. A successful exploitation could allow an attacker to iteratively navigate through the filesystem and ultimately download protected system…

  • CVE-2025-49511HigJun 10, 2025
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework civi-framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through <= 2.1.6.

  • CVE-2025-49454HigJun 10, 2025
    risk 0.53cvss 8.1epss 0.01

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean TinySalt tinysalt allows PHP Local File Inclusion.This issue affects TinySalt: from n/a through < 3.10.0.

  • CVE-2025-43701HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data.  This impacts OmniStudio: before version 254.

  • CVE-2025-43700HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted data.  This impacts OmniStudio: before Spring 2025.

  • CVE-2025-43697HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data. This impacts OmniStudio: before Spring 2025