VYPR

CVEs

118,369 total · page 465 of 2,368

  • CVE-2026-2627HigFeb 17, 2026
    risk 0.51cvss 7.8epss 0.00

    A security flaw has been discovered in Softland FBackup up to 9.9. This impacts an unknown function in the library C:\Program Files\Common Files\microsoft shared\ink\HID.dll of the component Backup/Restore. The manipulation results in link following. The attack needs to be…

  • CVE-2025-33088HigFeb 17, 2026
    risk 0.48cvss 7.4epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to incorrect file permissions for critical resources.

  • CVE-2026-2621HigFeb 17, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in Sciyon Koyuan Thermoelectricity Heat Network Management System 3.0. This affects an unknown part of the file /SISReport/WebReport20/Proxy/AsyncTreeProxy.aspx. The manipulation of the argument PGUID leads to sql injection. The attack…

  • CVE-2026-23595HigFeb 17, 2026
    risk 0.57cvss 8.8epss 0.00

    An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to create privileged user accounts. Successful exploitation could allow an attacker to gain administrative access,…

  • CVE-2025-13691HigFeb 17, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used to impersonate other users in the system.

  • CVE-2026-2620HigFeb 17, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in Huace Monitoring and Early Warning System 2.2. Affected by this issue is some unknown functionality of the file /Web/SysManage/ProjectRole.aspx. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the…

  • CVE-2025-70846HigFeb 17, 2026
    risk 0.46cvss 7.1epss 0.00

    lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) on the /tools/Password/add page in the input field password.

  • CVE-2025-67102HigFeb 17, 2026
    risk 0.49cvss 7.6epss 0.00

    A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands via the entity parameter.

  • CVE-2025-32355HigFeb 17, 2026
    risk 0.48cvss 7.3epss 0.01

    Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs in the HTTP request line, causing the proxy to load the given resource.

  • CVE-2026-2630HigFeb 17, 2026
    risk 0.57cvss 8.8epss 0.01

    A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted.

  • CVE-2026-26736HigFeb 17, 2026
    risk 0.57cvss 8.8epss 0.00

    TOTOLINK A3002RU_V3 V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the static_ipv6 parameter in the formIpv6Setup function.

  • CVE-2026-26732HigFeb 17, 2026
    risk 0.57cvss 8.8epss 0.00

    TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPassword` parameters in the formFilter function.

  • CVE-2026-26731HigFeb 17, 2026
    risk 0.57cvss 8.8epss 0.00

    TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.

  • CVE-2026-24734HigFeb 17, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate…

  • CVE-2025-36247HigFeb 17, 2026
    risk 0.46cvss 7.1epss 0.00

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive…

  • CVE-2024-55270HigFeb 17, 2026
    risk 0.57cvss 8.8epss 0.00

    phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter.

  • CVE-2026-23648HigFeb 17, 2026
    risk 0.51cvss 7.8epss 0.00

    Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permissive file permissions. Several binaries executed by the root user are writable and executable by unprivileged local users. An attacker with local access can…

  • CVE-2025-67905HigFeb 17, 2026
    risk 0.57cvss 8.7epss 0.00

    Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link, a related issue to CVE-2023-28892.…

  • CVE-2025-70828HigFeb 17, 2026
    risk 0.57cvss 8.8epss 0.00

    An issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configuration

  • CVE-2025-70397HigFeb 17, 2026
    risk 0.47cvss 7.2epss 0.00

    jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.

  • CVE-2025-65753HigFeb 17, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as root.

  • CVE-2026-2616HigFeb 17, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface. The manipulation leads to hard-coded credentials. The attack needs to be initiated within the local network. The exploit has…

  • CVE-2026-25087HigFeb 17, 2026
    risk 0.39cvss 7.0epss 0.01

    Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-buffering enabled, if the IPC file contains data with variadic buffers (such as…

  • CVE-2026-2615HigFeb 17, 2026
    risk 0.48cvss 7.2epss 0.12

    A flaw has been found in Wavlink WL-NU516U1 up to 20251208. The affected element is the function singlePortForwardDelete of the file /cgi-bin/firewall.cgi. Executing a manipulation of the argument del_flag can lead to command injection. The attack may be launched remotely. The…

  • CVE-2026-2247HigFeb 17, 2026
    risk 0.54cvss epss 0.00

    SQL injection vulnerability (SQLi) in Clicldeu SaaS, specifically in the generation of reports, which occurs when a previously authenticated remote attacker executes a malicious payload in the URL generated after downloading the student's report card in the ‘Day-to-day’…

  • CVE-2025-7631HigFeb 17, 2026
    risk 0.56cvss 8.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tumeva Internet Technologies Software Information Advertising and Consulting Services Trade Ltd. Co. Tumeva Prime News Software allows SQL Injection. This issue affects Tumeva…

  • CVE-2026-1216HigFeb 17, 2026
    risk 0.47cvss 7.2epss 0.00

    The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…

  • CVE-2026-2592HigFeb 17, 2026
    risk 0.43cvss 7.7epss 0.00

    The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Update in all versions up to and including 5.0.16. This is due to the payment callback handler 'Return_from_ZarinPal_Gateway' failing to validate that the…

  • CVE-2025-12062HigFeb 17, 2026
    risk 0.50cvss 8.8epss 0.01

    The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8.6 via the fc_load_template function. This makes it possible for authenticated…

  • CVE-2026-2474HigFeb 16, 2026
    risk 0.49cvss 7.5epss 0.00

    Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom(). The function does not validate that the length parameter is non-negative. If a negative value (e.g. -1) is supplied, the expression…

  • CVE-2026-2001HigFeb 16, 2026
    risk 0.57cvss 8.8epss 0.00

    The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'Notice::install_activate_plugin' function in all versions up to, and including, 2.1.3. This makes it possible for authenticated attackers, with…

  • CVE-2026-2567HigFeb 16, 2026
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was detected in Wavlink WL-NU516U1 20251208. This vulnerability affects the function sub_401218 of the file /cgi-bin/nas.cgi. Performing a manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack may be initiated remotely. The…

  • CVE-2026-2566HigFeb 16, 2026
    risk 0.47cvss 7.2epss 0.00

    A security vulnerability has been detected in Wavlink WL-NU516U1 up to 130/260. This affects the function sub_406194 of the file /cgi-bin/adm.cgi. Such manipulation of the argument firmware_url leads to stack-based buffer overflow. The attack can be launched remotely. The…

  • CVE-2019-25395HigFeb 16, 2026
    risk 0.47cvss 7.2epss 0.00

    Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious scripts through the HOSTNAME, KEYMAP, and OPENNESS parameters. Attackers can submit POST requests…

  • CVE-2019-25394HigFeb 16, 2026
    risk 0.47cvss 7.2epss 0.00

    Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the modem.cgi script that allow attackers to inject malicious scripts through POST parameters. Attackers can submit crafted payloads in parameters like INIT, HANGUP,…

  • CVE-2019-25379HigFeb 16, 2026
    risk 0.47cvss 7.2epss 0.00

    Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains stored and reflected cross-site scripting vulnerabilities in the urlfilter.cgi endpoint that allow attackers to inject malicious scripts. Attackers can submit POST requests with script payloads in the REDIRECT_PAGE or…

  • CVE-2026-2564HigFeb 16, 2026
    risk 0.53cvss 8.1epss 0.00

    A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak password recovery. It is possible to launch the attack remotely. Attacks of this…

  • CVE-2026-2101HigFeb 16, 2026
    risk 0.57cvss 8.7epss 0.00

    A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19 allows an attacker to execute arbitrary script code in user's browser session.

  • CVE-2026-26930HigFeb 16, 2026
    risk 0.47cvss 7.2epss 0.00

    SmarterTools SmarterMail before 9526 allows XSS via MAPI requests.

  • CVE-2025-65716HigFeb 16, 2026
    risk 0.57cvss 8.8epss 0.01

    An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a crafted .Md file.

  • CVE-2025-65715HigFeb 16, 2026
    risk 0.51cvss 7.8epss 0.00

    An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to execute arbitrary code when opening a crafted workspace.

  • CVE-2026-2447HigFeb 16, 2026
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.

  • CVE-2026-1335HigFeb 16, 2026
    risk 0.51cvss 7.8epss 0.00

    An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.

  • CVE-2026-1334HigFeb 16, 2026
    risk 0.51cvss 7.8epss 0.00

    An Out-Of-Bounds Read vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.

  • CVE-2026-1333HigFeb 16, 2026
    risk 0.51cvss 7.8epss 0.00

    A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT…

  • CVE-2026-1046HigFeb 16, 2026
    risk 0.49cvss 7.6epss 0.00

    Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577

  • CVE-2026-2549HigFeb 16, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in zhanghuanhao LibrarySystem 图书馆管理系统 up to 1.1.1. This impacts an unknown function of the file BookController.java. The manipulation leads to improper access controls. The attack is possible to be carried out remotely. The exploit…

  • CVE-2026-2544HigFeb 16, 2026
    risk 0.48cvss 7.3epss 0.03

    A security flaw has been discovered in yued-fe LuLu UI up to 3.0.0. This issue affects the function child_process.exec of the file run.js. The manipulation results in os command injection. The attack can be launched remotely. The vendor was contacted early about this disclosure…

  • CVE-2026-2542HigFeb 16, 2026
    risk 0.46cvss 7.0epss 0.00

    A weakness has been identified in Total VPN 0.5.29.0 on Windows. Affected by this vulnerability is an unknown functionality of the file C:\Program Files\Total VPN\win-service.exe. Executing a manipulation can lead to unquoted search path. It is possible to launch the attack on…

  • CVE-2026-2538HigFeb 16, 2026
    risk 0.46cvss 7.0epss 0.00

    A security flaw has been discovered in Flos Freeware Notepad2 4.2.22/4.2.23/4.2.24/4.2.25. Affected is an unknown function in the library Msimg32.dll. Performing a manipulation results in uncontrolled search path. Attacking locally is a requirement. The attack's complexity is…