VYPR

CVEs

117,533 total · page 486 of 2,351

  • CVE-2025-13845HigJan 15, 2026
    risk 0.51cvss 7.8epss 0.00

    CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.

  • CVE-2025-9014HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, caused by improper input validation.  A remote, unauthenticated attacker can exploit this flaw and cause Denial of Service on the web portal service.This…

  • CVE-2025-70307HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.

  • CVE-2025-36911HigJan 15, 2026
    risk 0.47cvss 7.1epss 0.07

    In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjacent) information disclosure of user's conversations and location with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2026-23493HigJan 15, 2026
    risk 0.49cvss 8.6epss 0.00

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file stores the $_COOKIE and $_SERVER variables, which means sensitive information such as database passwords, cookie session data, and other details can be accessed…

  • CVE-2026-22867HigJan 15, 2026
    risk 0.00cvss 8.7epss 0.00

    LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 3.8.0 to 4.3.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Interlinking feature. When a user creates a link to another document within the editor, the URL of that link is not…

  • CVE-2026-22265HigJan 15, 2026
    risk 0.00cvss 7.5epss 0.02

    Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to 8.2.8.2, command injection vulnerability exists in the log viewing functionality that allows authenticated users to execute arbitrary system commands. The vulnerability is in…

  • CVE-2025-70656HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the mac parameter of the sub_65B5C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-70308HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .gsf file.

  • CVE-2025-70304HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    A buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.

  • CVE-2025-70298HigJan 15, 2026
    risk 0.53cvss 8.2epss 0.00

    GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function.

  • CVE-2025-66417HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3.

  • CVE-2025-66292HigJan 15, 2026
    risk 0.46cvss 8.1epss 0.01

    DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vulnerability in the /api/common/attach/delete interface. Authenticated users can delete arbitrary files on the server via path traversal. When a user logs into…

  • CVE-2025-67246HigJan 15, 2026
    risk 0.47cvss 7.3epss 0.00

    A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control in the IOCTL handler. This driver exposes a device interface accessible to a normal user and handles attacker-controlled structures containing the lower 4GB of…

  • CVE-2025-67077HigJan 15, 2026
    risk 0.57cvss 8.8epss 0.00

    File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions also guest users, via the UploadTmpFile action.

  • CVE-2025-67076HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.01

    Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc controller and the ExternalGetFile action. Only files with an extension can be read.

  • CVE-2025-64516HigJan 15, 2026
    risk 0.00cvss 7.5epss 0.00

    GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this unauthorized access can be performed by an anonymous user. This…

  • CVE-2025-61973HigJan 15, 2026
    risk 0.57cvss 8.8epss 0.00

    A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL file during the installation process, which may result in unintended elevation of privileges.

  • CVE-2021-47784HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Cyberfox Web Browser 52.9.1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the search bar with excessive data. Attackers can generate a 9,000,000 byte payload and paste it into the search bar to trigger an application…

  • CVE-2021-47777HigJan 15, 2026
    risk 0.53cvss 8.2epss 0.00

    Build Smart ERP 21.0817 contains an unauthenticated SQL injection vulnerability in the 'eidValue' parameter of the login validation endpoint. Attackers can inject stacked SQL queries using payloads like ';WAITFOR DELAY '0:0:3'-- to manipulate database queries and potentially…

  • CVE-2021-47775HigJan 15, 2026
    risk 0.55cvss 8.4epss 0.00

    YouTube Video Grabber, now referred to as YouTube Downloader, 1.9.9.1 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the Structured Exception Handler. Attackers can craft a malicious payload of 712 bytes with SEH…

  • CVE-2021-47773HigJan 15, 2026
    risk 0.51cvss 7.8epss 0.00

    Dynojet Power Core 2.3.0 contains an unquoted service path vulnerability in the DJ.UpdateService that allows local authenticated users to potentially execute code with elevated privileges. Attackers can exploit the unquoted binary path by placing malicious executables in the…

  • CVE-2021-47767HigJan 15, 2026
    risk 0.51cvss 7.8epss 0.00

    10-Strike Network Inventory Explorer Pro 9.31 contains an unquoted service path vulnerability in the srvInventoryWebServer service running with LocalSystem privileges. Attackers can exploit the unquoted path by placing malicious executables in potential path segments to achieve…

  • CVE-2021-47766HigJan 15, 2026
    risk 0.46cvss 7.1epss 0.00

    Kmaleon 1.1.0.205 contains an authenticated SQL injection vulnerability in the 'tipocomb' parameter of kmaleonW.php that allows attackers to manipulate database queries. Attackers can exploit this vulnerability using boolean-based, error-based, and time-based blind SQL injection…

  • CVE-2021-47763HigJan 15, 2026
    risk 0.53cvss 8.2epss 0.00

    Aimeos 2021.10 LTS contains a SQL injection vulnerability in the json api 'sort' parameter that allows attackers to inject malicious database queries. Attackers can manipulate the sort parameter to reveal table and column names by sending crafted GET requests to the…

  • CVE-2021-47762HigJan 15, 2026
    risk 0.51cvss 7.8epss 0.00

    HTTPDebuggerPro 9.11 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables and…

  • CVE-2021-47761HigJan 15, 2026
    risk 0.51cvss 7.8epss 0.00

    MilleGPG5 5.7.2 contains a local privilege escalation vulnerability that allows authenticated users to modify service executable files in the MariaDB bin directory. Attackers can replace the mysqld.exe with a malicious executable, which will execute with system privileges when…

  • CVE-2021-47758HigJan 15, 2026
    risk 0.57cvss 8.8epss 0.01

    Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious PHP plugins through the module upload functionality. Authenticated attackers can generate and upload a ZIP plugin with a PHP backdoor…

  • CVE-2021-47757HigJan 15, 2026
    risk 0.57cvss 8.8epss 0.01

    Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability in the backup restoration functionality. Authenticated attackers can upload a modified backup zip file with a malicious PHP shell to execute arbitrary system commands on the…

  • CVE-2021-47755HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.01

    Oliver Library Server v5 contains a file download vulnerability that allows unauthenticated attackers to access arbitrary system files through unsanitized input in the FileServlet endpoint. Attackers can exploit the vulnerability by manipulating the 'fileName' parameter to…

  • CVE-2021-47752HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.01

    AWebServer GhostBuilding 18 contains a denial of service vulnerability that allows remote attackers to overwhelm the server by sending multiple concurrent HTTP requests. Attackers can generate high-volume requests to multiple endpoints including /mysqladmin to potentially crash…

  • CVE-2025-71019HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the wanSpeed parameter of the sub_65B5C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-70744HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the cloneType parameter of the sub_65B5C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2026-0897HigJan 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via…

  • CVE-2025-13062HigJan 15, 2026
    risk 0.50cvss 8.8epss 0.01

    The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.5.62. This is due to insufficient file type validation detecting JSON files, allowing double extension files to bypass sanitization while being accepted…

  • CVE-2026-22910HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.

  • CVE-2026-22909HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.01

    Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations.

  • CVE-2025-13455HigJan 14, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication and enroll an untrusted fingerprint.

  • CVE-2025-12166HigJan 14, 2026
    risk 0.42cvss 7.5epss 0.00

    The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection via the `order` and `append_where_sql` parameters in all versions up to, and including, 1.6.9.9 due to insufficient escaping on the user…

  • CVE-2026-23512HigJan 14, 2026
    risk 0.00cvss 8.6epss 0.00

    SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability when Advanced Options setting is trigger. The application executes notepad.exe without specifying an absolute path when using the Advanced Options setting. On…

  • CVE-2026-0861HigJan 14, 2026
    risk 0.55cvss 8.4epss 0.00

    Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that the attacker must have…

  • CVE-2026-23498HigJan 14, 2026
    risk 0.40cvss 7.2epss 0.00

    Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure not checked being against allow list for the map(...) override. This vulnerability is fixed in 6.7.6.1.

  • CVE-2026-23492HigJan 14, 2026
    risk 0.50cvss 8.8epss 0.00

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, an incomplete SQL injection patch in the Admin Search Find API allows an authenticated attacker to perform blind SQL injection. Although CVE-2023-30848 attempted to mitigate SQL…

  • CVE-2026-23477HigJan 14, 2026
    risk 0.50cvss 7.7epss 0.00

    Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1/oauth-apps.get is exposed to any authenticated user, regardless of their role or permissions. This endpoint returns an OAuth…

  • CVE-2025-33206HigJan 14, 2026
    risk 0.51cvss 7.8epss 0.01

    NVIDIA NSIGHT Graphics for Linux contains a vulnerability where an attacker could cause command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service.

  • CVE-2025-11224HigJan 14, 2026
    risk 0.50cvss 7.7epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to execute stored cross-site scripting through improper input validation in the Kubernetes…

  • CVE-2026-22856HigJan 14, 2026
    risk 0.53cvss 8.1epss 0.00

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑after‑free when one thread removes an entry from serial->IrpThreads while another reads it. This vulnerability is fixed in…

  • CVE-2025-71021HigJan 14, 2026
    risk 0.49cvss 7.5epss 0.00

    Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serverName parameter of the sub_65A28 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-70747HigJan 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serviceName parameter of the sub_65A28 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2026-21889HigJan 14, 2026
    risk 0.42cvss 7.5epss 0.00

    Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in…