VYPR

CVEs

117,440 total · page 520 of 2,349

  • CVE-2025-10883HigDec 16, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current…

  • CVE-2025-10882HigDec 16, 2025
    risk 0.51cvss 7.8epss 0.00

    AA maliciously crafted X_T file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current…

  • CVE-2025-10881HigDec 16, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current…

  • CVE-2025-9121HigDec 15, 2025
    risk 0.57cvss 8.8epss 0.00

    Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.

  • CVE-2023-53892HigDec 15, 2025
    risk 0.47cvss 7.2epss 0.01

    Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the jquery plugin manager. Attackers can upload a zip file with a PHP shell script and execute arbitrary system commands by accessing…

  • CVE-2023-53889HigDec 15, 2025
    risk 0.47cvss 7.2epss 0.01

    Perch CMS 3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload arbitrary PHP files through the assets management interface. Attackers can upload a malicious .phar file with embedded system command execution capabilities to execute…

  • CVE-2023-53888HigDec 15, 2025
    risk 0.57cvss 8.8epss 0.01

    Zomplog 3.9 contains a remote code execution vulnerability that allows authenticated attackers to inject and execute arbitrary PHP code through file manipulation endpoints. Attackers can upload files (such as JavaScript) and rename them to .php via the saveE and rename actions,…

  • CVE-2023-53886HigDec 15, 2025
    risk 0.49cvss 7.5epss 0.00

    Xlight FTP Server 3.9.3.6 contains a stack buffer overflow vulnerability in the 'Execute Program' configuration that allows attackers to crash the application. Attackers can trigger the vulnerability by inserting 294 characters into the program execution configuration, causing a…

  • CVE-2023-53885HigDec 15, 2025
    risk 0.47cvss 7.2epss 0.01

    Webutler v3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload PHP files with system command execution. Attackers can upload a PHAR file with embedded system commands to the media browser and execute arbitrary commands by…

  • CVE-2023-53883HigDec 15, 2025
    risk 0.47cvss 7.2epss 0.01

    Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page creation. Attackers can create a new PHP page with malicious system commands in the description field to execute arbitrary…

  • CVE-2023-53881HigDec 15, 2025
    risk 0.53cvss 8.1epss 0.00

    ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and execute arbitrary commands on Ruijie Reyee…

  • CVE-2023-53875HigDec 15, 2025
    risk 0.57cvss 8.8epss 0.00

    GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attackers can redirect victims using a malicious URL shortcut and WebDAV technique to run a reverse…

  • CVE-2023-53873HigDec 15, 2025
    risk 0.57cvss epss 0.01

    SyncBreeze 15.2.24 contains a denial of service vulnerability in the login authentication mechanism that allows attackers to crash the service. Attackers can send an oversized password parameter with repeated 'password=' values to overwhelm the login endpoint and potentially…

  • CVE-2023-53869HigDec 15, 2025
    risk 0.57cvss epss 0.01

    WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute dangerous PHP files through the media function. Attackers can leverage any created account to upload malicious PHP scripts that enable remote code execution on the…

  • CVE-2023-53868HigDec 15, 2025
    risk 0.57cvss 8.8epss 0.01

    Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code…

  • CVE-2025-14503HigDec 15, 2025
    risk 0.00cvss 7.2epss 0.01

    An overly-permissive IAM trust policy in the Harmonix on AWS framework may allow IAM principals in the same AWS account to escalate privileges via role assumption. The sample code for the EKS environment provisioning role is configured to trust the account root principal, which…

  • CVE-2025-65176HigDec 15, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Dynatrace OneAgent before 1.325.47. When attempting to access a remote network share from a machine where OneAgent is installed and receiving a "STATUS_LOGON_FAILURE" error, the agent will retrieve every user token on the machine and repeatedly attempt…

  • CVE-2025-66440HigDec 15, 2025
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/accounts/doctype/payment_entry/payment_entry.py is vulnerable to SQL Injection. It allows an attacker to extract arbitrary data from the database by injecting SQL…

  • CVE-2025-66439HigDec 15, 2025
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.accounts.doctype.payment_entry.payment_entry.py is vulnerable to SQL Injection. It allows an attacker to extract arbitrary data from the database by injecting SQL…

  • CVE-2025-66438HigDec 15, 2025
    risk 0.57cvss 8.8epss 0.00

    A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, the API frappe.www.printview.get_html_and_style() triggers the rendering of the html field inside a Print Format document using…

  • CVE-2025-66437HigDec 15, 2025
    risk 0.57cvss 8.8epss 0.01

    An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function renders address templates using frappe.render_template() with a context derived from the address_dict parameter, which can be either a…

  • CVE-2025-14038HigDec 15, 2025
    risk 0.46cvss 7.0epss 0.00

    EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. This could allow an attacker to read potentially sensitive data or possibly cause a denial-of-service by writing malformed data to certain gRPC endpoints. This…

  • CVE-2025-66434HigDec 15, 2025
    risk 0.57cvss 8.8epss 0.01

    An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (body_text) using frappe.render_template() with a user-supplied context (doc).…

  • CVE-2025-65742HigDec 15, 2025
    risk 0.53cvss 8.2epss 0.00

    An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execute a full account takeover via a crafted API request.

  • CVE-2025-11393HigDec 15, 2025
    risk 0.57cvss 8.7epss 0.00

    A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to…

  • CVE-2025-60786HigDec 15, 2025
    risk 0.57cvss 8.8epss 0.01

    A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via uploading a crafted Zip file.

  • CVE-2025-13824HigDec 15, 2025
    risk 0.57cvss epss 0.00

    A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red Fault LED and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become…

  • CVE-2025-13823HigDec 15, 2025
    risk 0.46cvss epss 0.00

    A security issue was found in the IPv6 stack in the Micro850 and Micro870 controllers when the controllers received multiple malformed packets during fuzzing. The controllers will go into recoverable fault with fault code 0xFE60. To recover the controller, clear the fault.

  • CVE-2024-44599HigDec 15, 2025
    risk 0.54cvss 8.3epss 0.00

    FNT Command 13.4.0 is vulnerable to Directory Traversal.

  • CVE-2024-44598HigDec 15, 2025
    risk 0.57cvss 8.8epss 0.00

    FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.

  • CVE-2025-34181HigDec 15, 2025
    risk 0.57cvss epss 0.01

    NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFILE request handler. An attacker with a valid Gateway Key can supply a crafted filename containing directory traversal sequences to write files to arbitrary…

  • CVE-2025-34180HigDec 15, 2025
    risk 0.55cvss epss 0.00

    NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a reversible encoding scheme. An attacker who obtains access to a deployed client configuration file…

  • CVE-2025-34179HigDec 15, 2025
    risk 0.57cvss epss 0.00

    NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gateway HTTPS request handling. The server evaluates request URIs using an unsanitized SQLite query against the FileLinks table in gateway.db. By injecting SQL…

  • CVE-2025-14383HigDec 15, 2025
    risk 0.42cvss 7.5epss 0.00

    The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' parameter in all versions up to, and including, 10.14.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2025-65781HigDec 15, 2025
    risk 0.00cvss 8.2epss 0.00

    An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorization bearer value as a userId and enters a non-terminating body-handling branch for any non-empty bearer token, enabling trivial…

  • CVE-2025-65780HigDec 15, 2025
    risk 0.00cvss 8.8epss 0.00

    An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire user document (beyond profile fields), including orgs/teams and loginDisabled, due to missing server-side authorization checks;…

  • CVE-2025-65779HigDec 15, 2025
    risk 0.00cvss 7.5epss 0.00

    An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a board's "sort" value (Boards.allow returns true without verifying userId), allowing arbitrary reordering of boards.

  • CVE-2025-65778HigDec 15, 2025
    risk 0.00cvss 8.1epss 0.00

    An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with attacker-controlled Content-Type (text/html), allowing execution of attacker-supplied HTML/JS in the application's origin and…

  • CVE-2025-14711HigDec 15, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability affects unknown code of the file /controller/api/hotelList.php. This manipulation of the argument pickedHotelName/type causes sql injection. The attack is…

  • CVE-2025-14710HigDec 15, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects an unknown part of the file /controller/api/OrderList.php. The manipulation of the argument telephone results in sql injection. The attack can be executed…

  • CVE-2025-14022HigDec 15, 2025
    risk 0.50cvss 7.7epss 0.00

    LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the application's network processing, causing server certificate verification to be disabled for a…

  • CVE-2025-14712HigDec 15, 2025
    risk 0.49cvss 7.5epss 0.00

    Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain test accounts and password.

  • CVE-2025-14549HigDec 15, 2025
    risk 0.00cvss 8.1epss 0.00

    In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR on Z processors incorrectly handles NUL (0x00) characters during the Latin-compatible charset (UTF-8, ISO8859-1, ASCII, etc) to IBM-1047/037 translation…

  • CVE-2025-13355HigDec 15, 2025
    risk 0.46cvss 7.1epss 0.00

    The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

  • CVE-2025-12684HigDec 15, 2025
    risk 0.46cvss 7.1epss 0.00

    The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in the page, leading to a reflected cross site scripting, which could be used against high-privilege users such as admins.

  • CVE-2025-14704HigDec 15, 2025
    risk 0.48cvss 7.3epss 0.12

    A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown function of the file /eshell of the component API. The manipulation results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be…

  • CVE-2025-67900HigDec 14, 2025
    risk 0.53cvss 8.1epss 0.00

    NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.

  • CVE-2025-14673HigDec 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in gmg137 snap7-rs up to 1.142.1. Affected is the function snap7_rs::client::S7Client::as_ct_write of the file /tests/snap7-rs/src/client.rs. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit…

  • CVE-2025-14672HigDec 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in gmg137 snap7-rs up to 1.142.1. This impacts the function TSnap7MicroClient::opWriteArea of the file s7_micro_client.cpp. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2025-14668HigDec 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of the file /query/loginExe.php. Performing a manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The…