VYPR

CVEs

117,423 total · page 540 of 2,349

  • CVE-2025-66263HigNov 26, 2025
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Null byte injection in download_setting.php allows…

  • CVE-2025-66252HigNov 26, 2025
    risk 0.49cvss 7.5epss 0.00

    Infinite Loop Denial of Service via Failed File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Infinite loop when unlink() fails in status_contents.php…

  • CVE-2025-65957HigNov 26, 2025
    risk 0.57cvss epss 0.00

    Core Bot Is an Open Source discord bot made for maple hospital servers. Prior to commit dffe050, the API keys (SUPABASE_API_KEY, TOKEN) are loaded using environment variables, but there are cases in code (error handling, summaries, webhooks) where configuration summaries may…

  • CVE-2025-65952HigNov 25, 2025
    risk 0.57cvss epss 0.00

    Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a path traversal vulnerability exists where complicated combinations of backslashes and periods can be used to escape the Gorilla Tag path and write to unwanted…

  • CVE-2025-62703HigNov 25, 2025
    risk 0.50cvss 8.8epss 0.01

    Fugue is a unified interface for distributed computing that lets users execute Python, Pandas, and SQL code on Spark, Dask, and Ray with minimal rewrites. In version 0.9.2 and prior, there is a remote code execution vulnerability by pickle deserialization via FlaskRPCServer. The…

  • CVE-2025-58360HigKEVNov 25, 2025
    risk 0.74cvss 8.2epss 0.65

    GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms…

  • CVE-2025-51741HigNov 25, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthenticated attacker to cause the server to send email verification messages to arbitrary users via the /sendEmailCodeForResetPwd endpoint potentially causing a denial of service to…

  • CVE-2025-9624HigNov 25, 2025
    risk 0.42cvss 7.5epss 0.01

    A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs. This issue affects all OpenSearch versions between 3.0.0 and < 3.3.0 and OpenSearch < 2.19.4.

  • CVE-2025-66017HigNov 25, 2025
    risk 0.46cvss epss 0.00

    CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiable abort, and a key refresh protocol. In versions 0.6.3 and prior of cggmp21 and version 0.7.0-alpha.1 of cggmp24, presignatures can be used in the way that…

  • CVE-2025-65965HigNov 25, 2025
    risk 0.46cvss epss 0.00

    Grype is a vulnerability scanner for container images and filesystems. A credential disclosure vulnerability was found in Grype, affecting versions 0.68.0 through 0.104.0. If registry credentials are defined and the output of grype is written using the --file or --output…

  • CVE-2025-12816HigNov 25, 2025
    risk 0.49cvss 8.6epss 0.01

    An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and…

  • CVE-2025-64065HigNov 25, 2025
    risk 0.57cvss 8.8epss 0.00

    The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The administrative LoginAs or user impersonation feature is vulnerable to a access control failure. This flaw allows any authenticated low-privileged user to…

  • CVE-2025-64064HigNov 25, 2025
    risk 0.57cvss 8.8epss 0.00

    Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SECURITY_PROFILE_ID. Because of weak access controls any low level user can use this API and change their permission to Administrator…

  • CVE-2025-34350HigNov 25, 2025
    risk 0.57cvss epss 0.01

    UnForm Server versions < 10.1.15 contain an unauthenticated arbitrary file read and SMB coercion vulnerability in the Doc Flow feature’s 'arc' endpoint. The Doc Flow module uses the 'arc' handler to retrieve and render pages or resources specified by the user-supplied 'pp'…

  • CVE-2025-64066HigNov 25, 2025
    risk 0.56cvss 8.6epss 0.00

    Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The endpoint fails to implement any authorization checks, allowing unauthenticated attackers to perform POST requests to register new user accounts in the…

  • CVE-2025-64062HigNov 25, 2025
    risk 0.57cvss 8.8epss 0.00

    The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the authenticated session. By manipulating the email parameter to an arbitrary value (e.g., [email protected]), an attacker can assume…

  • CVE-2025-33205HigNov 25, 2025
    risk 0.47cvss 7.3epss 0.00

    NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of functionality from an untrusted control sphere by use of a predefined variable. A successful exploit of this vulnerability may lead to code execution.

  • CVE-2025-33204HigNov 25, 2025
    risk 0.51cvss 7.8epss 0.00

    NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data created by an attacker could cause code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information…

  • CVE-2025-33203HigNov 25, 2025
    risk 0.49cvss 7.6epss 0.00

    NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Server-Side Request Forgery. A successful exploit of this vulnerability may lead to information disclosure and denial of service.

  • CVE-2025-33189HigNov 25, 2025
    risk 0.51cvss 7.8epss 0.00

    NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an out-of-bound write. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, information disclosure, or escalation of privileges.

  • CVE-2025-33188HigNov 25, 2025
    risk 0.52cvss 8.0epss 0.00

    NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware controls. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service.

  • CVE-2025-13483HigNov 25, 2025
    risk 0.57cvss epss 0.00

    SiRcom SMART Alert (SiSA) allows unauthorized access to backend APIs. This allows an unauthenticated attacker to bypass the login screen using browser developer tools, gaining access to restricted parts of the application.

  • CVE-2025-64050HigNov 25, 2025
    risk 0.40cvss 7.2epss 0.01

    A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors…

  • CVE-2025-40890HigNov 25, 2025
    risk 0.51cvss 7.9epss 0.00

    A Stored Cross-Site Scripting vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated low-privilege user can craft a malicious dashboard containing a JavaScript payload and share it with victim users, or…

  • CVE-2025-0248HigNov 25, 2025
    risk 0.53cvss 8.1epss 0.00

    HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input. A remote, unauthenticated attacker can specially craft a URL to execute script in a victim's Web browser within the security context of the…

  • CVE-2025-59371HigNov 25, 2025
    risk 0.49cvss epss 0.01

    An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated attacker could leverage this vulnerability to potentially gain unauthorized access to the device. This vulnerability does not affect Wi-Fi 7 series models. Refer…

  • CVE-2025-59370HigNov 25, 2025
    risk 0.49cvss epss 0.01

    A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary commands, leading to the device executing unintended instructions. Refer to the 'Security Update for ASUS Router…

  • CVE-2025-13502HigNov 25, 2025
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.

  • CVE-2025-13376HigNov 25, 2025
    risk 0.47cvss 7.2epss 0.01

    The ProjectList plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 0.3.0. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on the…

  • CVE-2025-12003HigNov 25, 2025
    risk 0.53cvss epss 0.01

    A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of the device. Refer to the ' Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.

  • CVE-2025-12742HigNov 25, 2025
    risk 0.49cvss epss 0.00

    A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Teradata driver parameters. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No…

  • CVE-2025-13068HigNov 25, 2025
    risk 0.40cvss 7.2epss 0.00

    The Telegram Bot & Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Telegram username in all versions up to, and including, 4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2025-59373HigNov 25, 2025
    risk 0.55cvss epss 0.00

    A local privilege escalation vulnerability exists in the restore mechanism of ASUS System Control Interface. It can be triggered when an unprivileged actor copies files without proper validation into protected system paths, potentially leading to arbitrary files being…

  • CVE-2025-9803HigNov 25, 2025
    risk 0.57cvss 8.8epss 0.00

    lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application fails to verify the 'aud' (audience) field in the access token issued by Google, which is crucial for ensuring the token is…

  • CVE-2025-65951HigNov 25, 2025
    risk 0.57cvss 8.7epss 0.00

    Inside Track / Entropy Derby is a research-grade horse-racing betting engine. Prior to commit 2d38d2f, the VDF-based timelock encryption system fails to enforce sequential delay against the betting operator. Bettors pre-compute the entire Wesolowski VDF and include vdfOutputHex…

  • CVE-2025-64761HigNov 25, 2025
    risk 0.40cvss 7.2epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in the system. Specifically…

  • CVE-2025-65018HigNov 25, 2025
    risk 0.00cvss 7.1epss 0.00

    LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, there is a heap buffer overflow vulnerability in the libpng simplified API function…

  • CVE-2025-64720HigNov 25, 2025
    risk 0.00cvss 7.1epss 0.00

    LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, an out-of-bounds read vulnerability exists in png_image_read_composite when processing palette images…

  • CVE-2025-62155HigNov 25, 2025
    risk 0.48cvss 8.5epss 0.00

    New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.9.6, a recently patched SSRF vulnerability contains a bypass method that can bypass the existing security fix and still allow SSRF to occur. Because the…

  • CVE-2025-54563HigNov 24, 2025
    risk 0.49cvss 7.5epss 0.00

    An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Incorrect Access Control, leading to Remote Information Disclosure.

  • CVE-2025-54338HigNov 24, 2025
    risk 0.49cvss 7.5epss 0.00

    An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to disclose user hashes.

  • CVE-2025-52538HigNov 24, 2025
    risk 0.52cvss 8.0epss 0.00

    Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, potentially resulting in loss of confidentiality or availability.

  • CVE-2025-48510HigNov 24, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability.

  • CVE-2025-0003HigNov 24, 2025
    risk 0.47cvss 7.3epss 0.00

    Inadequate lock protection within Xilinx Run time may allow a local attacker to trigger a Use-After-Free condition potentially resulting in loss of confidentiality or availability

  • CVE-2024-14007HigNov 24, 2025
    risk 0.57cvss epss 0.01

    Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) versions prior to 1.3.4 contain an authentication bypass in the NVMS-9000 control protocol. By sending a single crafted TCP payload to an exposed NVMS-9000 control…

  • CVE-2025-56400HigNov 24, 2025
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own…

  • CVE-2025-52539HigNov 24, 2025
    risk 0.47cvss 7.3epss 0.00

    A buffer overflow with Xilinx Run Time Environment may allow a local attacker to read or corrupt data from the advanced extensible interface (AXI), potentially resulting in loss of confidentiality, integrity, and/or availability.

  • CVE-2025-0005HigNov 24, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, potentially resulting in crash or denial of service.

  • CVE-2025-13609HigNov 24, 2025
    risk 0.46cvss 8.2epss 0.00

    A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform Module (TPM) device but claiming an existing agent's unique identifier (UUID). This action overwrites the legitimate agent's…

  • CVE-2025-63434HigNov 24, 2025
    risk 0.57cvss 8.8epss 0.00

    The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic integrity or authenticity check on their contents. An attacker…