VYPR

CVEs

117,423 total · page 542 of 2,349

  • CVE-2025-65106HigNov 21, 2025
    risk 0.47cvss epss 0.01

    LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template system that allows attackers to access Python object internals through template…

  • CVE-2025-65102HigNov 21, 2025
    risk 0.57cvss epss 0.00

    PJSIP is a free and open source multimedia communication library. Prior to version 2.16, Opus PLC may zero-fill the input frame as long as the decoder ptime, while the input frame length, which is based on stream ptime, may be less than that. This issue affects PJSIP users who…

  • CVE-2025-11935HigNov 21, 2025
    risk 0.00cvss 7.5epss 0.00

    With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when a server responded to a ClientHello containing psk_dhe_ke…

  • CVE-2025-11087HigNov 21, 2025
    risk 0.57cvss 8.8epss 0.00

    The Zegen Core plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 2.0.1. This is due to missing nonce validation and missing file type validation in the '/custom-font-code/custom-fonts-uploads.php' file.…

  • CVE-2025-62626HigNov 21, 2025
    risk 0.47cvss epss 0.00

    Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values.

  • CVE-2025-62609HigNov 21, 2025
    risk 0.42cvss 7.5epss 0.00

    MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer from external gguflib library is dereferenced without validation, causing…

  • CVE-2025-30201HigNov 21, 2025
    risk 0.00cvss 7.7epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a vulnerability in Wazuh Agent allows authenticated attackers to force NTLM authentication through malicious UNC paths in various agent configuration settings,…

  • CVE-2025-13132HigNov 21, 2025
    risk 0.48cvss 7.4epss 0.00

    This vulnerability allowed a site to enter fullscreen, after a user click, without a full-screen notification (toast) appearing. Without this notification, users could potentially be misled about what site they were on if a malicious site renders a fake UI (like a fake address…

  • CVE-2025-13470HigNov 21, 2025
    risk 0.42cvss 7.5epss 0.00

    In RNP version 0.18.0 a refactoring regression causes the symmetric session key used for Public-Key Encrypted Session Key (PKESK) packets to be left uninitialized except for zeroing, resulting in it always being an all-zero byte array. Any data encrypted using public-key…

  • CVE-2025-12973HigNov 21, 2025
    risk 0.47cvss 7.2epss 0.01

    The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeFile() function in all versions up to, and including, 1.7.8. This makes it possible for…

  • CVE-2025-13357HigNov 21, 2025
    risk 0.41cvss 7.4epss 0.01

    Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthenticated binds, this could result in…

  • CVE-2025-66095HigNov 21, 2025
    risk 0.55cvss 8.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.13.

  • CVE-2025-66073HigNov 21, 2025
    risk 0.47cvss 7.2epss 0.00

    Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue affects WP Webhooks: from n/a through <= 3.3.8.

  • CVE-2025-66055HigNov 21, 2025
    risk 0.47cvss 7.2epss 0.00

    Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Object Injection.This issue affects Email Subscribers & Newsletters: from n/a through <= 5.9.10.

  • CVE-2025-40210HigNov 21, 2025
    risk 0.42cvss 7.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: Revert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND" I've found that pynfs COMP6 now leaves the connection or lease in a strange state, which causes CLOSE9 to hang indefinitely. I've dug…

  • CVE-2025-13138HigNov 21, 2025
    risk 0.49cvss 7.5epss 0.02

    The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search' parameter of the select_2_ajax() function in all versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

  • CVE-2025-12160HigNov 21, 2025
    risk 0.47cvss 7.2epss 0.00

    The Simple User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpr_admin_msg' parameter in all versions up to, and including, 6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

  • CVE-2025-13156HigNov 21, 2025
    risk 0.50cvss 8.8epss 0.01

    The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the insert_media_attachment() function in all versions up to, and including, 3.3.0. This is due to the…

  • CVE-2025-13322HigNov 21, 2025
    risk 0.53cvss 8.1epss 0.01

    The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.0. This is due to the `wpag_uploadaudio_callback()` AJAX handler not properly validating user-supplied file paths…

  • CVE-2025-13159HigNov 21, 2025
    risk 0.46cvss 7.1epss 0.00

    The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.0.43. This is due to the plugin allowing SVG file uploads via an unauthenticated AJAX endpoint…

  • CVE-2025-12138HigNov 21, 2025
    risk 0.57cvss 8.8epss 0.01

    The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.0.6. This is due to the plugin relying on a user-controlled Content-Type HTTP header to validate file uploads in…

  • CVE-2025-12135HigNov 21, 2025
    risk 0.47cvss 7.2epss 0.00

    The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versions up to, and including, 1.0.6 due to a missing capability check on the save_custome_code() function. This makes it possible for unauthenticated attackers to…

  • CVE-2025-11985HigNov 21, 2025
    risk 0.57cvss 8.8epss 0.00

    The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'rp_save_property_settings' function in versions 0.1 to 0.4.1. This makes it possible for authenticated…

  • CVE-2025-64695HigNov 21, 2025
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitrary code may be executed with the privilege of the user invoking the installer.

  • CVE-2025-58097HigNov 21, 2025
    risk 0.51cvss 7.8epss 0.00

    The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files within the installation directory and execute arbitrary code with the administrative privilege.

  • CVE-2025-13499HigNov 21, 2025
    risk 0.51cvss 7.8epss 0.00

    Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service

  • CVE-2025-64751HigNov 21, 2025
    risk 0.50cvss 8.8epss 0.00

    OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <= docker <= v.1.11.0) are vulnerable to improper policy…

  • CVE-2025-62164HigNov 21, 2025
    risk 0.50cvss 8.8epss 0.01

    vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability could lead to a crash (denial-of-service) and potentially remote code execution (RCE), exists in the Completions API endpoint. When…

  • CVE-2025-13485HigNov 21, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in itsourcecode Online File Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The…

  • CVE-2025-64660HigNov 20, 2025
    risk 0.52cvss 8.0epss 0.01

    Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.

  • CVE-2025-64655HigNov 20, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-62459HigNov 20, 2025
    risk 0.54cvss 8.3epss 0.00

    Microsoft Defender Portal Spoofing Vulnerability

  • CVE-2025-62207HigNov 20, 2025
    risk 0.56cvss 8.6epss 0.01

    Azure Monitor Elevation of Privilege Vulnerability

  • CVE-2025-36072HigNov 20, 2025
    risk 0.57cvss 8.8epss 0.00

    IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration allow an authenticated user to execute arbitrary code on the system, caused by the deserialization of untrusted object graphs…

  • CVE-2025-61138HigNov 20, 2025
    risk 0.49cvss 7.5epss 0.00

    Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.

  • CVE-2025-25613HigNov 20, 2025
    risk 0.49cvss 7.5epss 0.00

    FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 were discovered to transmit cookies for their web based administrative application containing usernames and passwords. These were…

  • CVE-2025-48986HigNov 20, 2025
    risk 0.57cvss 8.8epss 0.01

    Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

  • CVE-2025-63889HigNov 20, 2025
    risk 0.49cvss 7.5epss 0.00

    The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary files via crafted file path in a template value.

  • CVE-2025-12121HigNov 20, 2025
    risk 0.47cvss 7.3epss 0.00

    Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized shell command construction. This function was used in project directory launching (core.lua), drag-and-drop file handling…

  • CVE-2025-12120HigNov 20, 2025
    risk 0.47cvss 7.3epss 0.00

    Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, without prompting the user for confirmation. The .lite_project.lua file is intended for project-specific configuration but can contain executable Lua logic. This…

  • CVE-2025-62730HigNov 20, 2025
    risk 0.57cvss 8.8epss 0.00

    SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, they are able to assign administrative permissions to any user including themselves. This allow a malicious…

  • CVE-2025-62294HigNov 20, 2025
    risk 0.49cvss 7.5epss 0.00

    SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recovery tokens, a malicious attacker is able to brute-force all possible values and takeover any account in reasonable amount of time. This issue was fixed in…

  • CVE-2025-41075HigNov 20, 2025
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the…

  • CVE-2025-41074HigNov 20, 2025
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the…

  • CVE-2025-40601HigNov 20, 2025
    risk 0.49cvss 7.5epss 0.01

    A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.

  • CVE-2025-13451HigNov 20, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of the file /action.php. Such manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly…

  • CVE-2025-13449HigNov 20, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument Password results in sql injection. The attack may be performed from remote. The exploit has been made public…

  • CVE-2025-13446HigNov 20, 2025
    risk 0.57cvss 8.8epss 0.04

    A vulnerability has been found in Tenda AC21 16.03.08.16. This vulnerability affects unknown code of the file /goform/SetSysTimeCfg. The manipulation of the argument timeZone/time leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The…

  • CVE-2025-13445HigNov 20, 2025
    risk 0.57cvss 8.8epss 0.04

    A flaw has been found in Tenda AC21 16.03.08.16. This affects an unknown part of the file /goform/SetIpMacBind. Executing a manipulation of the argument list can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be…

  • CVE-2025-13442HigNov 20, 2025
    risk 0.49cvss 7.3epss 0.20

    A security vulnerability has been detected in UTT 进取 750W up to 3.2.2-191225. Affected by this vulnerability is the function system of the file /goform/formPdbUpConfig. Such manipulation of the argument policyNames leads to command injection. The attack may be launched…