VYPR

CVEs

117,423 total · page 538 of 2,349

  • CVE-2024-45370HigDec 1, 2025
    risk 0.47cvss 7.3epss 0.00

    An authentication bypass vulnerability exists in the User profile management functionality of Socomec Easy Config System 2.6.1.0. A specially crafted database record can lead to unauthorized access. An attacker can modify a local database to trigger this vulnerability.

  • CVE-2024-39148HigDec 1, 2025
    risk 0.53cvss 8.1epss 0.01

    The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root when the service is reachable over network. Typically, the service is protected via local firewall.

  • CVE-2025-63528HigDec 1, 2025
    risk 0.55cvss 8.5epss 0.00

    A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the blooddinfo.php component. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript…

  • CVE-2025-63527HigDec 1, 2025
    risk 0.55cvss 8.5epss 0.00

    A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php and hprofile.php components. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject…

  • CVE-2025-63526HigDec 1, 2025
    risk 0.55cvss 8.5epss 0.00

    A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System within the abs.php component. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript payloads into…

  • CVE-2024-56089HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in Technitium through v13.2.2 enables attackers to conduct a DNS cache poisoning attack and inject fake responses by reviving the birthday attack.

  • CVE-2025-59789HigDec 1, 2025
    risk 0.42cvss 7.5epss 0.02

    Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1.15.0) on all platforms allows remote attackers to make the server crash via sending deep recursive json data. Root Cause: The bRPC json2pb component uses rapidjson to parse json data from the network.…

  • CVE-2025-41738HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.

  • CVE-2025-41700HigDec 1, 2025
    risk 0.51cvss 7.8epss 0.00

    An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.

  • CVE-2025-61619HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed

  • CVE-2025-61618HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed

  • CVE-2025-61617HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed

  • CVE-2025-61610HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed

  • CVE-2025-61609HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed

  • CVE-2025-61608HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed

  • CVE-2025-61607HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed

  • CVE-2025-3012HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    In dpc modem, there is a possible system crash due to null pointer dereference. This could lead to remote denial of service with no additional execution privileges needed

  • CVE-2025-13814HigDec 1, 2025
    risk 0.47cvss 7.3epss 0.01

    A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit…

  • CVE-2025-11133HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed

  • CVE-2025-11132HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed

  • CVE-2025-11131HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed

  • CVE-2025-13808HigDec 1, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerability is the function update of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/UserController.java of the component User Profile…

  • CVE-2025-13806HigDec 1, 2025
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthModule.java of the component Transaction…

  • CVE-2025-13803HigDec 1, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /mediacrush/paths.py of the component Header Handler. Such manipulation of the argument Host leads to improper neutralization of http headers for scripting syntax.…

  • CVE-2025-64772HigDec 1, 2025
    risk 0.51cvss 7.8epss 0.00

    The installer of INZONE Hub 1.0.10.3 to 1.0.17.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer.

  • CVE-2025-13792HigNov 30, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function eval of the file /html/st/stdeslocamento/request/getResumo.php. Performing a manipulation of the argument passageiros results in code injection. Remote…

  • CVE-2025-13788HigNov 30, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Chanjet CRM up to 20251106. The impacted element is an unknown function of the file /tools/upgradeattribute.php. The manipulation of the argument gblOrgID leads to sql injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2025-13786HigNov 30, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. Performing manipulation of the argument content results in code injection. It is possible to initiate the attack remotely. The…

  • CVE-2025-13782HigNov 30, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is the function delete of the file application/Admin/Controller/SlideController.class.php of the component SlideController. The manipulation of the argument ids…

  • CVE-2025-66423HigNov 30, 2025
    risk 0.46cvss 7.1epss 0.00

    Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

  • CVE-2025-66289HigNov 29, 2025
    risk 0.57cvss 8.8epss 0.00

    OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user is disabled or when a password change occurs, allowing active session cookies to remain valid indefinitely. As a…

  • CVE-2025-66225HigNov 29, 2025
    risk 0.57cvss 8.8epss 0.00

    OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the username submitted in the final reset request matches the account for which the reset process was originally initiated. After…

  • CVE-2025-66224HigNov 29, 2025
    risk 0.57cvss 8.8epss 0.01

    OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains an input-neutralization flaw in its mail configuration and delivery workflow that allows user-controlled values to flow directly into the system’s sendmail…

  • CVE-2025-66223HigNov 29, 2025
    risk 0.55cvss epss 0.00

    OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not expire once issued, remain valid even after the invited user is removed from the organization, and allow multiple invitations to the same email with different…

  • CVE-2025-66217HigNov 29, 2025
    risk 0.00cvss 7.5epss 0.01

    AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, an integer underflow vulnerability exists in the MQTT parsing logic of AIS-catcher. This vulnerability allows an attacker to trigger a massive Heap Buffer Overflow by sending a malformed MQTT packet with a…

  • CVE-2025-53899HigNov 29, 2025
    risk 0.47cvss 7.2epss 0.01

    Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is vulnerable to an incorrectly specified destination in a communication channel which allows an attacker with administrative privileges on the system under…

  • CVE-2025-53896HigNov 29, 2025
    risk 0.46cvss 7.1epss 0.00

    Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could cause under certain circumstances that a user's active session would not properly time out due to inactivity. This issue has been patched in version 9.1.0.

  • CVE-2025-66201HigNov 29, 2025
    risk 0.53cvss 8.1epss 0.00

    LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-side Request Forgery (SSRF), by passing specially crafted OpenAPI specs to its "Actions" feature and making the LLM use those actions. It could be used by an…

  • CVE-2025-12183HigNov 28, 2025
    risk 0.50cvss epss 0.01

    Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.

  • CVE-2025-51735HigNov 28, 2025
    risk 0.49cvss 7.5epss 0.00

    CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.

  • CVE-2025-12638HigNov 28, 2025
    risk 0.45cvss 8.0epss 0.01

    Keras version 3.11.3 is affected by a path traversal vulnerability in the keras.utils.get_file() function when extracting tar archives. The vulnerability arises because the function uses Python's tarfile.extractall() method without the security-critical filter='data' parameter.…

  • CVE-2025-13768HigNov 28, 2025
    risk 0.49cvss 7.5epss 0.00

    WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log into the system as any user by modifying a specific parameter. Attackers must first obtain a user ID to exploit this vulnerability.

  • CVE-2025-66384HigNov 28, 2025
    risk 0.53cvss 8.2epss 0.00

    app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.

  • CVE-2025-58308HigNov 28, 2025
    risk 0.47cvss 7.3epss 0.00

    Vulnerability of improper criterion security check in the call module. Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2025-58302HigNov 28, 2025
    risk 0.55cvss 8.4epss 0.00

    Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-58316HigNov 28, 2025
    risk 0.47cvss 7.3epss 0.00

    DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58310HigNov 28, 2025
    risk 0.52cvss 8.0epss 0.00

    Permission control vulnerability in the distributed component. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-58303HigNov 28, 2025
    risk 0.55cvss 8.4epss 0.00

    UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-66360HigNov 28, 2025
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) information to li-admin users. This can lead to privilege escalation.

  • CVE-2025-66359HigNov 28, 2025
    risk 0.55cvss 8.5epss 0.00

    An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multiple components leads to a cross-site scripting (XSS) vulnerability.