VYPR

CVEs

117,405 total · page 560 of 2,349

  • CVE-2025-11843HigOct 31, 2025
    risk 0.57cvss epss 0.00

    Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On-Premises contain an account impersonation vulnerability. A malicious user may potentially be able to impersonate the web service account or the account of a service using the API…

  • CVE-2025-62232HigOct 31, 2025
    risk 0.42cvss 7.5epss 0.00

    Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has been fixed in the following…

  • CVE-2025-30189HigOct 31, 2025
    risk 0.48cvss 7.4epss 0.01

    When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally…

  • CVE-2025-30188HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict information that is required to operate the web frontend, which leads to unavailability of the component. Please deploy the provided updates and patch releases. No…

  • CVE-2025-10897HigOct 31, 2025
    risk 0.56cvss 8.6epss 0.02

    The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php…

  • CVE-2025-7846HigOct 31, 2025
    risk 0.57cvss 8.8epss 0.01

    The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() function in all versions up to, and including, 16.7. This makes it possible for authenticated attackers, with…

  • CVE-2025-54763HigOct 31, 2025
    risk 0.47cvss 7.2epss 0.01

    FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web UI of the product may execute an arbitrary OS command.

  • CVE-2025-8849HigOct 31, 2025
    risk 0.00cvss 7.5epss 0.00

    LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key` and `value` parameters accept arbitrarily large inputs without proper validation, leading to a null pointer error in the…

  • CVE-2025-6176HigOct 31, 2025
    risk 0.42cvss 7.5epss 0.01

    Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less…

  • CVE-2025-52664HigOct 31, 2025
    risk 0.50cvss 8.8epss 0.01

    SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users

  • CVE-2025-52663HigOct 31, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to the UniFi Talk management network to invoke internal debug operations through the device API. …

  • CVE-2025-48984HigOct 31, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

  • CVE-2025-48982HigOct 31, 2025
    risk 0.51cvss 7.8epss 0.00

    This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.

  • CVE-2025-34298HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.01

    Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied to email identity state,…

  • CVE-2025-34287HigOct 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because the file was writable by www-data, an attacker with web server privileges could modify its contents,…

  • CVE-2025-34286HigOct 30, 2025
    risk 0.47cvss 7.2epss 0.02

    Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient validation/escaping of parameters used to build backend command lines allows an authenticated administrator to inject shell…

  • CVE-2025-34284HigOct 30, 2025
    risk 0.58cvss 8.8epss 0.04

    Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters allows an authenticated administrator to inject shell metacharacters that are incorporated into backend command invocations.…

  • CVE-2025-34280HigOct 30, 2025
    risk 0.47cvss 7.2epss 0.01

    Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation. An authenticated administrator can trigger command execution on the…

  • CVE-2025-34134HigOct 30, 2025
    risk 0.47cvss 7.2epss 0.02

    Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligence (BPI) component. Insufficient validation and sanitization of administrator-controlled BPI configuration parameters (notably bpi_logfile and bpi_configfile)…

  • CVE-2024-58273HigOct 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands as the Apache web user (or the backend shell user) to escalate to root on the host.

  • CVE-2024-14009HigOct 30, 2025
    risk 0.47cvss 7.2epss 0.01

    Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The System Profile feature is an administrative diagnostic/configuration capability. Due to improper access controls and unsafe handling of exported/imported…

  • CVE-2024-14008HigOct 30, 2025
    risk 0.47cvss 7.2epss 0.02

    Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizard. Insufficient validation of user-supplied input allows an authenticated administrator to inject shell metacharacters that are incorporated into backend…

  • CVE-2024-14005HigOct 30, 2025
    risk 0.58cvss 8.8epss 0.04

    Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient validation of user-supplied input in the wizard allows an authenticated administrator to inject shell metacharacters that are incorporated into backend command…

  • CVE-2024-14004HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.01

    Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenticated user could manipulate NagVis configuration data or leverage insufficiently validated configuration settings to obtain…

  • CVE-2024-13995HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.01

    Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes…

  • CVE-2023-7322HigOct 30, 2025
    risk 0.53cvss 8.1epss 0.01

    Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevertheless able to invoke API endpoints, resulting in unintended access to data and actions exposed via the API. This incorrect…

  • CVE-2023-7317HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.02

    Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, low-privileged attacker could access or interact with the terminal interface without sufficient authorization, potentially allowing unauthorized command…

  • CVE-2021-47700HigOct 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly permissive ownership/permissions under the Apache user. Local or co-hosted processes could read/overwrite export artifacts or manipulate paths, risking disclosure or tampering and…

  • CVE-2021-47693HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.01

    The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.3 / Nagios XI 5.8.5 contains a SQL injection vulnerability in the search text handling. Unsanitized user-supplied input was incorporated into SQL queries used by configuration object editors, allowing…

  • CVE-2020-36869HigOct 30, 2025
    risk 0.47cvss 7.2epss 0.02

    Nagios XI versions prior to 5.7.5 contain a SQL injection vulnerability in the SNMP Trap Interface edit page. Exploitation requires an account with administrative privileges to access the affected interface. A user with administrative access could supply crafted input that is…

  • CVE-2020-36868HigOct 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Nagios XI versions prior to 5.7.3 contain a privilege escalation vulnerability in the getprofile.sh helper script. The script performed profile retrieval and initialization routines using insecure file/command handling and insufficient validation of attacker-controlled inputs,…

  • CVE-2020-36867HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.03

    Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values used in the PDF generation pipeline or the wrapper that invokes offline/pdf helper utilities were insufficiently validated or…

  • CVE-2020-36863HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.01

    Nagios XI versions prior to 5.7.2 allow PHP files to be uploaded to the Audio Import directory and executed from that location. The upload handler did not properly restrict file types or enforce storage outside of the webroot, and the web server permitted execution within the…

  • CVE-2020-36859HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.01

    The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple SQL injection vulnerabilities in the object edit pages. Unsanitized user-supplied input was incorporated into SQL queries used by configuration object editors, allowing…

  • CVE-2020-36857HigOct 30, 2025
    risk 0.47cvss 7.2epss 0.02

    Nagios XI versions prior to 5.6.14 contain a post-authentication SQL injection vulnerability in the SNMP Trap Interface page. Exploitation requires an account with administrative privileges to access the affected interface. A user with administrative access could supply…

  • CVE-2020-36856HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.02

    Nagios XI versions prior to 5.6.14 contain an authenticated remote command execution vulnerability in the CCM command_test.php script. Insufficient validation of the `address` parameter allows an authenticated user with access to the Core Config Manager to inject shell…

  • CVE-2018-25123HigOct 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Nagios XI versions prior to 5.5.7 contain a privilege escalation vulnerability in the MRTG graphing component. MRTG-related processes/scripts executed with excessive privileges, allowing a local attacker with limited system access to abuse file/command execution paths or…

  • CVE-2018-25122HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.02

    Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component Download page. The download/import handler used unsafe command construction with attacker-controlled input and lacked sufficient validation and output encoding, allowing an…

  • CVE-2016-15050HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.01

    Nagios XI versions prior to 5.2.4 contain a SQL injection vulnerability in the notification search functionality. User-supplied search parameters were incorporated into SQL statements without adequate parameterization or sanitation, allowing an authenticated user to manipulate…

  • CVE-2013-10073HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.03

    Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-controlled input is passed to a shell without adequate sanitation or argument quoting, allowing an authenticated user with access to discovery functionality to…

  • CVE-2011-10035HigOct 30, 2025
    risk 0.46cvss 7.0epss 0.00

    Nagios XI versions prior to 2011R1.9 contain privilege escalation vulnerabilities in the scripts that install or update system crontab entries. Due to time-of-check/time-of-use race conditions and missing synchronization or final-path validation, a local low-privileged user…

  • CVE-2025-8850HigOct 30, 2025
    risk 0.00cvss 8.8epss 0.00

    In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow. The system allows users to disable 2FA without requiring a valid OTP or backup code, bypassing the intended verification process. This vulnerability occurs…

  • CVE-2025-63423HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator password.

  • CVE-2025-61498HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (DoS) via supplying a crafted packet.

  • CVE-2025-61141HigOct 30, 2025
    risk 0.42cvss 7.5epss 0.01

    sqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the openEditor function passes the EDITOR environment variable and config file path to sh -c without sanitization, allowing attackers to execute arbitrary commands.

  • CVE-2025-3356HigOct 30, 2025
    risk 0.56cvss 8.6epss 0.00

    IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view, overwrite, or append to arbitrary files on the…

  • CVE-2025-3355HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

  • CVE-2025-63422HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to arbitrarily change the administrator username and password via sending a crafted GET request.

  • CVE-2025-63298HigOct 30, 2025
    risk 0.53cvss 8.2epss 0.00

    A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/manage_website.php component. An authenticated user with administrative privileges can leverage this flaw by submitting a specially crafted POST request,…

  • CVE-2025-36137HigOct 30, 2025
    risk 0.47cvss 7.2epss 0.00

    IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Control Center Director (CCD) users that could allow a privileged user to escalate…