VYPR

CVEs

117,423 total · page 534 of 2,349

  • CVE-2025-58098HigDec 5, 2025
    risk 0.47cvss 8.3epss 0.01

    Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version…

  • CVE-2025-13654HigDec 5, 2025
    risk 0.42cvss 7.5epss 0.01

    A stack buffer overflow vulnerability exists in the buffer_get function of duc, a disk management tool, where a condition can evaluate to true due to underflow, allowing an out-of-bounds read.

  • CVE-2025-59775HigDec 5, 2025
    risk 0.42cvss 7.5epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade…

  • CVE-2025-55753HigDec 5, 2025
    risk 0.42cvss 7.5epss 0.00

    An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects…

  • CVE-2025-13614HigDec 5, 2025
    risk 0.53cvss 8.1epss 0.00

    The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cool_tag_cloud' shortcode in all versions up to, and including, 2.29 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

  • CVE-2025-12879HigDec 5, 2025
    risk 0.57cvss 8.8epss 0.00

    The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2. This is due to missing nonce validation in the "Import Using CSV File" function. This makes it possible for unauthenticated attackers to…

  • CVE-2025-12851HigDec 5, 2025
    risk 0.46cvss 8.1epss 0.01

    The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.32 via the 'controller' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the…

  • CVE-2025-12850HigDec 5, 2025
    risk 0.42cvss 7.5epss 0.00

    The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versions up to, and including, 3.6.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. …

  • CVE-2025-12181HigDec 5, 2025
    risk 0.50cvss 8.8epss 0.01

    The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the cstu_update_post() function in all versions up to, and including, 1.3.7. This makes it possible for authenticated attackers, with Author-level access and…

  • CVE-2025-12154HigDec 5, 2025
    risk 0.57cvss 8.8epss 0.01

    The Auto Thumbnailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadThumb() function in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with Contributor-level access and…

  • CVE-2025-12153HigDec 5, 2025
    risk 0.57cvss 8.8epss 0.01

    The Featured Image via URL plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation function in all versions up to, and including, 0.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload…

  • CVE-2025-13066HigDec 5, 2025
    risk 0.50cvss 8.8epss 0.01

    The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.0.6. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a…

  • CVE-2025-66564HigDec 4, 2025
    risk 0.42cvss 7.5epss 0.00

    Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided OID (which is untrusted data) on periods. Similarly, function api.getContentType splits…

  • CVE-2025-66561HigDec 4, 2025
    risk 0.47cvss 7.3epss 0.00

    SysReptor is a fully customizable pentest reporting platform. Prior to 2025.102, there is a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated users to execute malicious JavaScript in the context of other logged-in users by uploading malicious JavaScript files…

  • CVE-2025-66559HigDec 4, 2025
    risk 0.52cvss epss 0.00

    Taiko Alethia is an Ethereum-equivalent, permissionless, based rollup designed to scale Ethereum without compromising its fundamental properties. In 2.3.1 and earlier, TaikoInbox._verifyBatches (packages/protocol/contracts/layer1/based/TaikoInbox.sol:627-678) advanced the local…

  • CVE-2025-13373HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands.

  • CVE-2025-66506HigDec 4, 2025
    risk 0.42cvss 7.5epss 0.00

    Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.3, function identity.extractIssuerURL splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in…

  • CVE-2025-66238HigDec 4, 2025
    risk 0.47cvss 7.2epss 0.00

    DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appliance's virtual console could exploit these features to redirect network traffic, potentially accessing restricted services or data on the host machine.

  • CVE-2025-53704HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account.

  • CVE-2025-1547HigDec 4, 2025
    risk 0.47cvss 7.2epss 0.00

    A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.

  • CVE-2025-1545HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from the Firebox configuration through an exposed authentication or management web interface. This vulnerability only affects Firebox systems…

  • CVE-2025-13932HigDec 4, 2025
    risk 0.54cvss epss 0.00

    The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference (IDOR), where any authenticated user can access detailed data of any plant by altering the plant_id in the request.

  • CVE-2025-12196HigDec 4, 2025
    risk 0.47cvss 7.2epss 0.01

    An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.

  • CVE-2025-12195HigDec 4, 2025
    risk 0.47cvss 7.2epss 0.01

    An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI commands.

  • CVE-2025-12026HigDec 4, 2025
    risk 0.47cvss 7.2epss 0.00

    An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.

  • CVE-2025-11838HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.01

    A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.

  • CVE-2025-10285HigDec 4, 2025
    risk 0.48cvss epss 0.00

    The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv2 hash which an attacker could use to crack the user's domain password.

  • CVE-2025-66575HigDec 4, 2025
    risk 0.51cvss 7.8epss 0.00

    VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges. Attackers can exploit this by providing a malicious service name, allowing them to inject commands…

  • CVE-2025-66573HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this…

  • CVE-2025-66555HigDec 4, 2025
    risk 0.57cvss epss 0.01

    AirKeyboard iOS App 1.0.5 contains a missing authentication vulnerability that allows unauthenticated attackers to type arbitrary keystrokes directly into the victim's iOS device in real-time without user interaction, resulting in full remote input control.

  • CVE-2025-65959HigDec 4, 2025
    risk 0.50cvss 8.7epss 0.00

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Stored XSS vulnerability was discovered in Open-WebUI's Notes PDF download functionality. An attacker can import a Markdown file containing malicious SVG tags…

  • CVE-2025-63896HigDec 4, 2025
    risk 0.49cvss 7.6epss 0.00

    An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to inject arbitrary keystrokes via a spoofed Bluetooth HID device.

  • CVE-2025-55948HigDec 4, 2025
    risk 0.47cvss 7.3epss 0.00

    This vulnerability fundamentally arises from yzcheng90 X-SpringBoot 6.0's implementation of role-based access control (RBAC) through dual dependency on frontend menu systems and backend permission tables, without enforcing atomic synchronization between these components. The…

  • CVE-2025-27935HigDec 4, 2025
    risk 0.56cvss epss 0.01

    The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authentication state without verifying the OTP, thereby bypassing multi-factor authentication.

  • CVE-2025-13543HigDec 4, 2025
    risk 0.57cvss 8.8epss 0.01

    The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'PostGalleryUploader' class functions in all versions up to, and including, 1.12.5. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2024-58278HigDec 4, 2025
    risk 0.55cvss epss 0.00

    perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scripts. Attackers can control the 0th argument of packed executables to execute another executable, allowing them to bypass restrictions and…

  • CVE-2024-58277HigDec 4, 2025
    risk 0.57cvss epss 0.00

    R Radio Network FM Transmitter 1.07 allows unauthenticated attackers to access the admin user's password through the system.cgi endpoint, enabling authentication bypass and FM station setup access.

  • CVE-2024-58276HigDec 4, 2025
    risk 0.57cvss epss 0.00

    Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can use UNION-based injection to extract sensitive information from the users table…

  • CVE-2024-58275HigDec 4, 2025
    risk 0.57cvss epss 0.02

    Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save endpoint that suffers from a parameter injection flaw. Attackers can inject shell metacharacters to execute arbitrary commands on the server.

  • CVE-2023-53734HigDec 4, 2025
    risk 0.57cvss epss 0.01

    dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially gain administrative access.

  • CVE-2025-65958HigDec 4, 2025
    risk 0.49cvss 8.5epss 0.04

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Server-Side Request Forgery (SSRF) vulnerability in Open WebUI allows any authenticated user to force the server to make HTTP requests to arbitrary URLs. This…

  • CVE-2025-65883HigDec 4, 2025
    risk 0.55cvss 8.4epss 0.00

    A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local network attacker to achieve Remote Code Execution (RCE) with root privileges. The issue occurs due to improper session invalidation after administrator logout.…

  • CVE-2025-12995HigDec 4, 2025
    risk 0.53cvss 8.1epss 0.00

    Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances. This issue affects CareLink Network: before December 4, 2025.

  • CVE-2025-12097HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.01

    There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure.  Successful exploitation requires an attacker to send a specially crafted request to the NI System Web Server, allowing the attacker to read arbitrary files.…

  • CVE-2025-65945HigDec 4, 2025
    risk 0.42cvss 7.5epss 0.00

    auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Applications are affected when they…

  • CVE-2025-65637HigDec 4, 2025
    risk 0.42cvss 7.5epss 0.01

    A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe…

  • CVE-2025-14015HigDec 4, 2025
    risk 0.57cvss 8.8epss 0.01

    A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /goform/aspForm. This manipulation of the argument param causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available…

  • CVE-2025-63363HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows attackers to execute de-authentication attacks, allowing crafted deauthentication and disassociation…

  • CVE-2025-66516HigDec 4, 2025
    risk 0.54cvss 8.4epss 0.80

    Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. This CVE covers the same…

  • CVE-2025-66287HigDec 4, 2025
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.