VYPR

CVEs

117,402 total · page 564 of 2,349

  • CVE-2025-12338HigOct 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability affects unknown code of the file /admin/admin_product.ph. Executing a manipulation of the argument pid can lead to sql injection. The attack may be launched remotely. The…

  • CVE-2025-12337HigOct 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file /admin/admin_feature.php. Performing a manipulation of the argument pid results in sql injection. The attack may be initiated remotely. The exploit…

  • CVE-2025-12336HigOct 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_index.php. Such manipulation of the argument Username leads to sql injection. The attack can be launched remotely.…

  • CVE-2025-43024HigOct 28, 2025
    risk 0.49cvss 7.5epss 0.00

    A GUI dialog of an application allows to view what files are in the file system without proper authorization.

  • CVE-2025-62260HigOct 27, 2025
    risk 0.42cvss 7.5epss 0.00

    Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number of objects returned from Headless API requests, which allows remote attackers to…

  • CVE-2025-62725HigOct 27, 2025
    risk 0.52cvss epss 0.14

    Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile…

  • CVE-2025-12326HigOct 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5. This vulnerability affects unknown code of the file /process.php of the component POST Request Handler. The manipulation of the argument un results in sql injection. The attack can be…

  • CVE-2025-12325HigOct 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2025-12322HigOct 27, 2025
    risk 0.57cvss 8.8epss 0.01

    A flaw has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function fromNatStaticSetting of the file /goform/NatStaticSetting. Executing a manipulation of the argument page can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has…

  • CVE-2025-12316HigOct 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in code-projects Courier Management System 1.0. This impacts an unknown function of the file /courier/edit-courier.php. The manipulation of the argument OfficeName leads to sql injection. The attack is possible to be carried out remotely. The…

  • CVE-2025-61105HigOct 27, 2025
    risk 0.00cvss 7.5epss 0.00

    FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

  • CVE-2025-61102HigOct 27, 2025
    risk 0.00cvss 7.5epss 0.00

    FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

  • CVE-2025-61101HigOct 27, 2025
    risk 0.00cvss 7.5epss 0.00

    FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

  • CVE-2025-59151HigOct 27, 2025
    risk 0.46cvss 8.2epss 0.00

    Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface before 6.3 is vulnerable to Carriage Return Line Feed (CRLF) injection. When a request is made to a file ending with…

  • CVE-2025-58356HigOct 27, 2025
    risk 0.47cvss epss 0.00

    Constellation is the first Confidential Kubernetes. The Constellation CVM image uses LUKS2-encrypted volumes for persistent storage. When opening an encrypted storage device, the CVM uses the libcryptsetup function crypt_activate_by_passhrase. If the VM is successful in opening…

  • CVE-2025-61100HigOct 27, 2025
    risk 0.00cvss 7.5epss 0.00

    FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions.

  • CVE-2025-61099HigOct 27, 2025
    risk 0.00cvss 7.5epss 0.00

    FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet.

  • CVE-2025-36007HigOct 27, 2025
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escalation due to improper privilege assignment to an update script.

  • CVE-2025-12309HigOct 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in code-projects Nero Social Networking Site 1.0. This affects an unknown part of the file /friendprofile.php. Executing manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2025-12308HigOct 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in code-projects Nero Social Networking Site 1.0. Affected by this issue is some unknown functionality of the file /deletemessage.php. Performing manipulation of the argument message_id results in sql injection. It is possible to initiate the…

  • CVE-2025-12307HigOct 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in code-projects Nero Social Networking Site 1.0. Affected by this vulnerability is an unknown functionality of the file /addfriend.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The…

  • CVE-2025-12306HigOct 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in code-projects Nero Social Networking Site 1.0. Affected is an unknown function of the file /acceptoffres.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2025-55752HigOct 27, 2025
    risk 0.47cvss 7.5epss 0.67

    Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the …

  • CVE-2025-12363HigOct 27, 2025
    risk 0.49cvss 7.5epss 0.00

    Email Password Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

  • CVE-2025-12301HigOct 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /editproduct.php. Such manipulation of the argument photo leads to unrestricted upload. The attack can be launched remotely. The exploit has…

  • CVE-2025-54968HigOct 27, 2025
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In some configurations, this may allow remote users to submit jobs, or local users to submit jobs that will execute with the permissions of other users.

  • CVE-2025-27225HigOct 27, 2025
    risk 0.50cvss 7.5epss 0.17

    TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive internal information including PII to unauthenticated attackers.

  • CVE-2025-27223HigOct 27, 2025
    risk 0.49cvss 7.5epss 0.02

    TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies…

  • CVE-2025-27222HigOct 27, 2025
    risk 0.56cvss 8.6epss 0.02

    TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traversal sequences to be included. This can be used to read any…

  • CVE-2025-61247HigOct 27, 2025
    risk 0.53cvss 8.2epss 0.00

    indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in the password parameter of login.php.

  • CVE-2025-60425HigOct 27, 2025
    risk 0.56cvss 8.6epss 0.01

    Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.

  • CVE-2025-60424HigOct 27, 2025
    risk 0.49cvss 7.6epss 0.01

    A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.

  • CVE-2025-34133HigOct 27, 2025
    risk 0.46cvss epss 0.00

    Wimi Teamwork versions prior to 7.38.17 contains a cross-site request forgery (CSRF) vulnerability in its API. The API accepts any authenticated request that contains a JSON field named 'csrf_token' without validating the field’s value; only the presence of the field is…

  • CVE-2025-12293HigOct 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in SourceCodester Point of Sales 1.0. This issue affects some unknown processing of the file /category.php. Such manipulation of the argument Category leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly…

  • CVE-2025-12292HigOct 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in SourceCodester Point of Sales 1.0. This vulnerability affects unknown code of the file /index.php. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly…

  • CVE-2023-49440HigOct 27, 2025
    risk 0.57cvss 8.8epss 0.00

    AhnLab EPP 1.0.15 is vulnerable to SQL Injection via the "preview parameter."

  • CVE-2025-61482HigOct 27, 2025
    risk 0.47cvss 7.2epss 0.00

    Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By hooking into app crypto routines and intercepting decryption paths, attacker can recover…

  • CVE-2025-52268HigOct 27, 2025
    risk 0.49cvss 7.5epss 0.00

    StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a hardcoded AES key which allows attackers to forge or decrypt valid login tokens.

  • CVE-2025-52264HigOct 27, 2025
    risk 0.52cvss 8.0epss 0.00

    StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at download.cgi.

  • CVE-2025-9164HigOct 27, 2025
    risk 0.57cvss epss 0.00

    Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checking system directories, allowing local privilege escalation through malicious DLL placement.This…

  • CVE-2025-52263HigOct 27, 2025
    risk 0.52cvss 8.0epss 0.00

    An issue in the Web Configuration module of Startcharge Artemis AC Charger 7-22 kW v1.0.4 allows authenticated network-adjacent attackers to upload crafted firmware, leading to arbitrary code execution.

  • CVE-2025-12286HigOct 27, 2025
    risk 0.46cvss 7.0epss 0.00

    A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)\VeePN\avservice\avservice.exe of the component AVService. This manipulation causes unquoted search path. The attack requires local access. A high degree of…

  • CVE-2025-41068HigOct 27, 2025
    risk 0.49cvss 7.5epss 0.00

    Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. This is achieved by sending the creation of an NF with an invalid type via SBI and then requesting its data. The NRF executes a check that…

  • CVE-2025-41067HigOct 27, 2025
    risk 0.49cvss 7.5epss 0.00

    Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. An SBI request that deletes the NRF's own registry causes a check that ends up crashing the NRF process and renders the discovery service…

  • CVE-2025-12277HigOct 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in Abdullah-Hasan-Sajjad Online-School up to f09dda77b4c29aa083ff57f4b1eb991b98b68883. This affects an unknown part of the file /studentLogin.php. This manipulation of the argument Email causes sql injection. The attack is possible to be carried out…

  • CVE-2025-12274HigOct 27, 2025
    risk 0.57cvss 8.8epss 0.01

    A security vulnerability has been detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument page leads to buffer overflow. Remote exploitation of the attack is possible.…

  • CVE-2025-12273HigOct 27, 2025
    risk 0.57cvss 8.8epss 0.01

    A weakness has been identified in Tenda CH22 1.0.0.1. Affected is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. Executing a manipulation of the argument page can lead to buffer overflow. The attack may be launched remotely. The exploit has been…

  • CVE-2025-12272HigOct 27, 2025
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in Tenda CH22 1.0.0.1. This impacts the function fromAddressNat of the file /goform/addressNat. Performing a manipulation of the argument page results in buffer overflow. The attack may be initiated remotely. The exploit has been released to…

  • CVE-2025-12271HigOct 27, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Tenda CH22 1.0.0.1. This affects the function fromRouteStatic of the file /goform/RouteStatic. Such manipulation of the argument page leads to buffer overflow. The attack can be launched remotely. The exploit is publicly available and might be…

  • CVE-2025-11955HigOct 27, 2025
    risk 0.53cvss epss 0.00

    Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the tunnel even if it does not receive an OCSP response or if the OCSP response signature is invalid.