VYPR

CVEs

117,442 total · page 517 of 2,349

  • CVE-2025-46291HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.2. An app may bypass Gatekeeper checks.

  • CVE-2025-46281HigDec 17, 2025
    risk 0.57cvss 8.8epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to break out of its sandbox.

  • CVE-2025-43529HigKEVDec 17, 2025
    risk 0.70cvss 8.8epss 0.09

    A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to…

  • CVE-2025-66646HigDec 17, 2025
    risk 0.49cvss 7.5epss 0.01

    RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. A vulnerability was discovered in the IPv6 fragmentation reassembly implementation of RIOT OS v2025.07. When receiving an…

  • CVE-2025-66397HigDec 17, 2025
    risk 0.54cvss 8.3epss 0.00

    ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reloadKiosk, and identifyKiosk functions in the Kiosk Manager feature suffers from broken access control, allowing any authenticated user to allow and accept kiosk…

  • CVE-2025-66396HigDec 17, 2025
    risk 0.47cvss 7.2epss 0.00

    ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/UserEditor.php` file. When an administrator saves a user's configuration settings, the keys of the `type` POST parameter array are not properly…

  • CVE-2025-34442HigDec 17, 2025
    risk 0.03cvss 7.5epss 0.01

    AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata includes full server paths to media files, revealing underlying filesystem structure and facilitating more effective attack chains.

  • CVE-2025-34441HigDec 17, 2025
    risk 0.03cvss 7.5epss 0.01

    AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Responses include emails, usernames, administrative status, and last login times, enabling user enumeration and privacy violations.

  • CVE-2025-34438HigDec 17, 2025
    risk 0.00cvss 8.1epss 0.00

    AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation metadata of any video. The endpoint verifies upload capability but fails to enforce ownership or management rights for the…

  • CVE-2025-34437HigDec 17, 2025
    risk 0.00cvss 8.8epss 0.00

    AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentication but omits ownership checks, allowing attackers to perform unauthorized uploads to arbitrary video objects.

  • CVE-2025-34436HigDec 17, 2025
    risk 0.00cvss 8.8epss 0.00

    AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object reference. The upload functionality verifies authentication but does not enforce ownership checks.

  • CVE-2025-67174HigDec 17, 2025
    risk 0.49cvss 7.5epss 0.01

    A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the admin_language_file and default_page_language_file in the admin.php component

  • CVE-2025-67171HigDec 17, 2025
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.

  • CVE-2025-66953HigDec 17, 2025
    risk 0.57cvss 8.8epss 0.00

    CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary code via the Web-based management interface and specifically the /system_setup.htm, /set_clock.htm, /receiver_setup.htm, /cal.htm?..., and /channel_setup.htm…

  • CVE-2025-66395HigDec 17, 2025
    risk 0.57cvss 8.8epss 0.00

    ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/ListEvents.php` file. When filtering events by type, the `WhichType` POST parameter is not properly sanitized or type-casted before being used in…

  • CVE-2024-46062HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This flaw allows a local low-privileged user…

  • CVE-2024-46060HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local low-privileged user to…

  • CVE-2025-67172HigDec 17, 2025
    risk 0.47cvss 7.2epss 0.01

    RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.

  • CVE-2025-66923HigDec 17, 2025
    risk 0.47cvss 7.2epss 0.01

    A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the phone_number parameter.

  • CVE-2025-65203HigDec 17, 2025
    risk 0.00cvss 7.1epss 0.00

    KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directive and iframe attribute sandbox, allowing attacker-controlled script in the sandboxed document to access populated form fields and…

  • CVE-2025-67285HigDec 17, 2025
    risk 0.47cvss 7.3epss 0.00

    A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using QR-Code v1.0. The reason for this issue is that attackers inject malicious code from the parameter 'id' and use it directly in SQL queries without the need for…

  • CVE-2025-66921HigDec 17, 2025
    risk 0.47cvss 7.2epss 0.01

    A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter.

  • CVE-2025-53919HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates a temporary folder, with weak permissions, during installation and uninstallation. A low-privileged attacker with local access could potentially exploit this,…

  • CVE-2025-53398HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions,

  • CVE-2025-43873HigDec 17, 2025
    risk 0.57cvss epss 0.00

    Successful exploitation of these vulnerabilities could allow an attacker to modify firmware and gain full access to the device.

  • CVE-2025-14727HigDec 17, 2025
    risk 0.54cvss 8.3epss 0.00

    A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2024-29371HigDec 17, 2025
    risk 0.49cvss 7.5epss 0.00

    In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and…

  • CVE-2025-61736HigDec 17, 2025
    risk 0.46cvss epss 0.00

    Successful exploitation of this vulnerability could result in the product failing to re-establish communication once the certificate expires.

  • CVE-2025-14097HigDec 17, 2025
    risk 0.47cvss 7.2epss 0.00

    A vulnerability in the application software of multiple Radiometer products may allow remote code execution and unauthorized device management when specific internal conditions are met. Exploitation requires that a remote connection is established with additional information…

  • CVE-2025-14096HigDec 17, 2025
    risk 0.55cvss 8.4epss 0.00

    A vulnerability exists in multiple Radiometer products that allow an attacker with physical access to the analyzer possibility to extract credential information. The vulnerability is due to a weakness in the design and insufficient credential protection in operating system. …

  • CVE-2025-14101HigDec 17, 2025
    risk 0.46cvss 7.1epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in GG Soft Software Services Inc. PaperWork allows Exploitation of Trusted Identifiers. This issue affects PaperWork: from 5.2.0.9427 before 6.0.

  • CVE-2025-11924HigDec 17, 2025
    risk 0.42cvss 7.5epss 0.00

    The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.13.2. This is due to the plugin not properly verifying that a user is authorized before the…

  • CVE-2025-11901HigDec 17, 2025
    risk 0.46cvss epss 0.00

    An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a…

  • CVE-2025-14305HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    ListCheck.exe developed by Acer has a Local Privilege Escalation vulnerability. Authenticated local attackers can replace ListCheck.exe with a malicious executable of the same name, which will be executed by the system and result in privilege escalation.

  • CVE-2025-53524HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    Fuji Electric Monitouch V-SFT-6 is vulnerable to an out-of-bounds write while processing a specially crafted project file, which may allow an attacker to execute arbitrary code.

  • CVE-2025-14701HigDec 17, 2025
    risk 0.46cvss 7.1epss 0.00

    An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification.

  • CVE-2025-14766HigDec 16, 2025
    risk 0.57cvss 8.8epss 0.03

    Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-14765HigDec 16, 2025
    risk 0.57cvss 8.8epss 0.03

    Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-68274HigDec 16, 2025
    risk 0.42cvss 7.5epss 0.01

    SIPGO is a library for writing SIP services in the GO language. Starting in version 0.3.0 and prior to version 1.0.0-alpha-1, a nil pointer dereference vulnerability is in the SIPGO library's `NewResponseFromRequest` function that affects all normal SIP operations. The…

  • CVE-2025-53619HigDec 16, 2025
    risk 0.48cvss 7.4epss 0.00

    An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.The function…

  • CVE-2025-53618HigDec 16, 2025
    risk 0.48cvss 7.4epss 0.00

    An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.The function…

  • CVE-2025-52582HigDec 16, 2025
    risk 0.48cvss 7.4epss 0.00

    An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2025-48429HigDec 16, 2025
    risk 0.48cvss 7.4epss 0.00

    An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to leaking heap data. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2025-68156HigDec 16, 2025
    risk 0.42cvss 7.5epss 0.00

    Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform recursive traversal over user-provided data structures without enforcing a maximum…

  • CVE-2025-68155HigDec 16, 2025
    risk 0.42cvss 7.5epss 0.01

    @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unauthenticated arbitrary file read during development mode. An attacker can read any file accessible to…

  • CVE-2025-68154HigDec 16, 2025
    risk 0.47cvss 8.1epss 0.13

    systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is directly concatenated into a PowerShell…

  • CVE-2025-65593HigDec 16, 2025
    risk 0.57cvss 8.8epss 0.00

    nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality.

  • CVE-2025-14553HigDec 16, 2025
    risk 0.46cvss epss 0.00

    Exposure of password hashes through an unauthenticated API response in TP-Link Tapo app on iOS and Android for Tapo cameras, allowing attackers to brute force the password in the local network. Issue can be mitigated through mobile application updates. Device firmware remains…

  • CVE-2025-52196HigDec 16, 2025
    risk 0.49cvss 7.5epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Ctera Portal 8.1.x (8.1.1417.24) allows remote attackers to induce the server to make arbitrary HTTP requests via a crafted HTML file containing an iframe.

  • CVE-2025-33235HigDec 16, 2025
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Resiliency Extension for Linux contains a vulnerability in the checkpointing core, where an attacker may cause a race condition. A successful exploit of this vulnerability might lead to information disclosure, data tampering, denial of service, or escalation of privileges.