VYPR

CVEs

117,407 total · page 557 of 2,349

  • CVE-2025-54526HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Fuji Electric Monitouch V-SFT-6 is vulnerable to a stack-based buffer overflow while processing a specially crafted project file, which may allow an attacker to execute arbitrary code.

  • CVE-2025-54496HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted project file may cause a heap-based buffer overflow in Fuji Electric Monitouch V-SFT-6, which may allow the attacker to execute arbitrary code.

  • CVE-2025-32786HigNov 4, 2025
    risk 0.42cvss 7.5epss 0.07

    The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Versions 1.5.0 and below are vulnerable to SQL Injection. This issue is fixed in version 1.5.1.

  • CVE-2024-56426HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000. The lack of a length check leads to out-of-bounds writes via malformed USB packets to the target.

  • CVE-2025-49494HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 9110, Modem 5123. Mishandling of an 5G NRMM packet leads to a Denial of Service.

  • CVE-2025-23358HigNov 4, 2025
    risk 0.53cvss 8.2epss 0.00

    NVIDIA NVApp for Windows contains a vulnerability in the installer, where a local attacker can cause a search path element issue. A successful exploit of this vulnerability might lead to code execution and escalation of privileges.

  • CVE-2025-54334HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in the NPU driver in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500. There is a NULL Pointer Dereference of hdev in the __npu_vertex_bootup function.

  • CVE-2025-52513HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results in an out-of-bounds write, leading to a denial of service.

  • CVE-2025-52512HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results in out-of-bounds memory access, leading to a denial of service.

  • CVE-2025-54332HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is a NULL Pointer Dereference of profiler.node in the npu_vertex_profileoff function.

  • CVE-2025-54329HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The function used to send a multiple-payloads message…

  • CVE-2025-54323HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in the camera in Samsung Mobile Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, and 1580. Improper debug printing leads to information leakage.

  • CVE-2025-41345HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDenunciasById.php'.

  • CVE-2025-41344HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_archivo' in '/backend/api/verArchivo.php'.

  • CVE-2025-41343HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'email' in '/backend/api/users/searchUserByEmail.php'.

  • CVE-2025-41342HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_user' in '/backend/api/buscarUsuarioId.php'.

  • CVE-2025-41341HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'seguro' in '/backend/api/buscarUsuarioByDenuncia.php'.

  • CVE-2025-41340HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_tp_denuncia' and 'id_sociedad' in '/backend/api/buscarTipoDenunciabyId.php'.

  • CVE-2025-41339HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_sociedad' in '/backend/api/buscarTipoDenuncia.php'.

  • CVE-2025-41338HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarTestigoByIdDenunciaUsuario.php'.

  • CVE-2025-41337HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarSSOParametros.php'.

  • CVE-2025-41336HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarConfiguracionParametros.php'.

  • CVE-2025-41335HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id' and ' 'id_sociedad' in '/api/buscarEmpresaById.php'.

  • CVE-2025-41114HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDocumentosByIdDenunciaUsuario.php'.

  • CVE-2025-41113HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/api/buscarDenunciaByPin.php'.

  • CVE-2025-41112HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarConfiguracionParametros2.php'.

  • CVE-2025-41111HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/api/buscarComentariosByDenuncia.php'.

  • CVE-2025-11690HigNov 4, 2025
    risk 0.55cvss 8.5epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability exists in the vehicleId parameter, allowing unauthorized access to sensitive information of other users’ vehicles. Exploiting this issue enables an attacker to retrieve data such as GPS coordinates, encryption keys,…

  • CVE-2025-20742HigNov 4, 2025
    risk 0.52cvss 8.0epss 0.00

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2025-20737HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435343; Issue ID: MSV-4040.

  • CVE-2025-20735HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435349; Issue ID: MSV-4051.

  • CVE-2025-20733HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00441509; Issue ID: MSV-4138.

  • CVE-2025-20728HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In wlan STA driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00447115; Issue ID: MSV-4276.

  • CVE-2025-20727HigNov 4, 2025
    risk 0.53cvss 8.1epss 0.01

    In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not…

  • CVE-2025-20726HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is…

  • CVE-2025-20725HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.01

    In ims service, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is…

  • CVE-2025-11890HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    The Crypto Payment Gateway with Payeer for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 1.0.3. This is due to the plugin not properly verifying a payments status through server-side validation though the…

  • CVE-2025-11733HigNov 4, 2025
    risk 0.40cvss 7.2epss 0.00

    The Footnotes Made Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 3.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

  • CVE-2025-11724HigNov 4, 2025
    risk 0.57cvss 8.8epss 0.01

    The EM Beer Manager plugin for WordPress is vulnerable to arbitrary file upload leading to remote code execution in all versions up to, and including, 3.2.3. This is due to missing file type validation in the EMBM_Admin_Untappd_Import_image() function and missing authorization…

  • CVE-2025-11704HigNov 4, 2025
    risk 0.42cvss 7.5epss 0.01

    The Elegance Menu plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the 'elegance-menu' attribute of the `elegance-menu` shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above,…

  • CVE-2025-10896HigNov 4, 2025
    risk 0.57cvss 8.8epss 0.01

    Multiple plugins for WordPress with the Jewel Theme Recommended Plugins Library are vulnerable to Unrestricted Upload of File with Dangerous Type via arbitrary plugin installation in all versions up to, and including, 1.0.2.3. This is due to missing capability checks on the…

  • CVE-2025-47368HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when dereferencing an invalid userspace address in a user buffer during MCDM IOCTL processing.

  • CVE-2025-47367HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while accessing a buffer during IOCTL processing.

  • CVE-2025-47365HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing large input data from a remote source via a communication interface.

  • CVE-2025-47361HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when triggering a subsystem crash with an out-of-range identifier.

  • CVE-2025-47360HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing client message during device management.

  • CVE-2025-47357HigNov 4, 2025
    risk 0.52cvss 8.0epss 0.00

    Information Disclosure when a user-level driver performs QFPROM read or write operations on Fuse regions.

  • CVE-2025-47353HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing request sent from GVM.

  • CVE-2025-47352HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing audio streaming operations.

  • CVE-2025-27074HigNov 4, 2025
    risk 0.57cvss 8.8epss 0.00

    Memory corruption while processing a GP command response.