VYPR

CVEs

117,459 total · page 503 of 2,350

  • CVE-2025-15216HigDec 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Tenda AC23 16.03.07.52. This impacts the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the argument bindnum leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is…

  • CVE-2025-15215HigDec 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in Tenda AC10U 15.03.06.48/15.03.06.49. This affects the function formSetPPTPUserList of the file /goform/setPptpUserList of the component HTTP POST Request Handler. This manipulation of the argument list causes buffer overflow. It is possible to…

  • CVE-2025-69235HigDec 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.

  • CVE-2025-69217HigDec 30, 2025
    risk 0.50cvss 7.7epss 0.00

    coturn is a free open source implementation of TURN and STUN Server. Versions 4.6.2r5 through 4.7.0-r4 have a bad random number generator for nonces and port randomization after refactoring. Additionally, random numbers aren't generated with openssl's RAND_bytes but libc's…

  • CVE-2025-68036HigDec 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CubeWP: from n/a through <= 1.1.27.

  • CVE-2025-23554HigDec 30, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakub Glos Off Page SEO off-page-seo allows Reflected XSS.This issue affects Off Page SEO: from n/a through <= 3.0.3.

  • CVE-2025-23550HigDec 30, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kemal YAZICI Product Puller product-puller allows Reflected XSS.This issue affects Product Puller: from n/a through <= 1.5.1.

  • CVE-2025-23469HigDec 30, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sleekplan Sleekplan sleekplan allows Reflected XSS.This issue affects Sleekplan: from n/a through <= 0.2.0.

  • CVE-2025-23458HigDec 30, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rakessh Ads24 Lite wp-ad-management allows Reflected XSS.This issue affects Ads24 Lite: from n/a through <= 1.0.

  • CVE-2025-15208HigDec 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in code-projects Refugee Food Management System 1.0. Affected by this issue is some unknown functionality of the file /home/editrefugee.php. The manipulation of the argument rfid results in sql injection. The attack can be launched remotely.…

  • CVE-2025-15207HigDec 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/view_products.php. The manipulation of the argument chkId[] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2025-15206HigDec 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /admin/add_area.php. Executing a manipulation of the argument txtAreaCode can lead to sql injection. The attack may be performed from remote. The exploit has been…

  • CVE-2024-25183HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.01

    givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.

  • CVE-2024-30855HigDec 29, 2025
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_action.php.

  • CVE-2025-67255HigDec 29, 2025
    risk 0.57cvss 8.8epss 0.01

    In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulnerability.

  • CVE-2025-67254HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.02

    NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.

  • CVE-2025-13592HigDec 29, 2025
    risk 0.40cvss 7.2epss 0.01

    The Advanced Ads plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 via the 'change-ad__content' shortcode parameter. This allows authenticated attackers with editor-level permissions or above, to execute code on the server.

  • CVE-2025-68861HigDec 29, 2025
    risk 0.46cvss 7.1epss 0.00

    Missing Authorization vulnerability in pluginoptimizer Plugin Optimizer plugin-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Plugin Optimizer: from n/a through <= 1.3.7.

  • CVE-2025-66877HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8.

  • CVE-2025-55061HigDec 29, 2025
    risk 0.57cvss 8.8epss 0.00

    CWE-434 Unrestricted Upload of File with Dangerous Type

  • CVE-2025-15198HigDec 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in code-projects College Notes Uploading System 1.0. This issue affects some unknown processing of the file /login.php. Executing a manipulation of the argument User can lead to sql injection. The attack may be launched remotely. The exploit has…

  • CVE-2025-68870HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in reDim GmbH CookieHint WP cookiehint-wp allows PHP Local File Inclusion.This issue affects CookieHint WP: from n/a through <= 1.0.0.

  • CVE-2025-66869HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Buffer overflow vulnerability in function strcat in asan_interceptors.cpp in libming 0.4.8.

  • CVE-2025-66866HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

  • CVE-2025-66865HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

  • CVE-2025-66864HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

  • CVE-2025-66863HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

  • CVE-2025-66862HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.00

    A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

  • CVE-2025-15196HigDec 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in code-projects Assessment Management 1.0. This affects an unknown part of the file login.php. Such manipulation of the argument userid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be…

  • CVE-2025-69211HigDec 29, 2025
    risk 0.41cvss 7.4epss 0.00

    Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL encoding middleware bypass. A NestJS application is vulnerable if it uses `@nestjs/platform-fastify`; relies on `NestMiddleware` (via `MiddlewareConsumer`)…

  • CVE-2025-69200HigDec 29, 2025
    risk 0.42cvss 7.5epss 0.02

    phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can trigger generation of a configuration backup ZIP via `POST /api/setup/backup` and then download the generated ZIP from a web-accessible location. The ZIP contains…

  • CVE-2025-68879HigDec 29, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in councilsoft Content Grid Slider content-grid-slider allows Reflected XSS.This issue affects Content Grid Slider: from n/a through <= 1.5.

  • CVE-2025-68878HigDec 29, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prasadkirpekar Advanced Custom CSS advanced-custom-css allows Reflected XSS.This issue affects Advanced Custom CSS: from n/a through <= 1.1.0.

  • CVE-2025-68877HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cedcommerce CedCommerce Integration for Good Market ced-good-market-integration allows PHP Local File Inclusion.This issue affects CedCommerce Integration for…

  • CVE-2025-68876HigDec 29, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in INVELITY Invelity SPS connect invelity-sps-connect allows Reflected XSS.This issue affects Invelity SPS connect: from n/a through <= 1.0.8.

  • CVE-2025-15195HigDec 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file /admin/add-module.php. This manipulation of the argument linked[] causes sql injection. The attack can be initiated remotely. The exploit…

  • CVE-2025-15193HigDec 29, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. This affects the function sub_423848 of the file /boafrm/formParentControl. Performing manipulation of the argument submit-url results in buffer overflow. The attack is possible to be carried out remotely. The exploit…

  • CVE-2025-15190HigDec 29, 2025
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in D-Link DWR-M920 up to 1.1.50. Impacted is the function sub_42261C of the file /boafrm/formFilter. The manipulation of the argument ip6addr results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been…

  • CVE-2025-15189HigDec 29, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in D-Link DWR-M920 up to 1.1.50. This issue affects the function sub_464794 of the file /boafrm/formDefRoute. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely. The exploit is publicly…

  • CVE-2025-15186HigDec 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in code-projects Refugee Food Management System 1.0. Affected by this issue is some unknown functionality of the file /home/addusers.php. Such manipulation of the argument a leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2025-15185HigDec 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in code-projects Refugee Food Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /home/refugeesreport.php. This manipulation of the argument a causes sql injection. It is possible to initiate the attack remotely.…

  • CVE-2025-15184HigDec 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in code-projects Refugee Food Management System 1.0. Affected is an unknown function of the file /home/refugeesreport2.php. The manipulation of the argument a results in sql injection. The attack may be performed from remote. The exploit is now…

  • CVE-2025-15183HigDec 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This impacts an unknown function of the file /home/viewtakenfd.php. The manipulation of the argument tfid leads to sql injection. The attack is possible to be carried out remotely.…

  • CVE-2025-15182HigDec 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown function of the file /home/served.php. Executing manipulation of the argument refNo can lead to sql injection. The attack can be executed remotely. The exploit has been…

  • CVE-2025-15181HigDec 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in code-projects Refugee Food Management System 1.0. The impacted element is an unknown function of the file /home/pagenateRefugeesList.php. Performing manipulation of the argument rfid results in sql injection. Remote exploitation of the…

  • CVE-2025-15180HigDec 29, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was identified in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/webExcptypemanFilte of the component HTTP Request Handler. Such manipulation of the argument page leads to stack-based buffer overflow. The attack may be…

  • CVE-2025-15227HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.01

    BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

  • CVE-2025-15179HigDec 29, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was determined in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/qossetting. This manipulation of the argument page causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and…

  • CVE-2025-15178HigDec 29, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was found in Tenda WH450 1.0.0.18. This issue affects some unknown processing of the file /goform/VirtualSer of the component HTTP Request Handler. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely.…

  • CVE-2025-15225HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.01

    WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to read arbitrary system files.