VYPR

CVEs

117,402 total · page 566 of 2,349

  • CVE-2025-11238HigOct 25, 2025
    risk 0.40cvss 7.2epss 0.00

    The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP Referer header in versions less than, or equal to, 3.4.4 due to insufficient input sanitization and output escaping when the "Save source URL" option is enabled. This makes it possible…

  • CVE-2025-34503HigOct 24, 2025
    risk 0.46cvss epss 0.00

    Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker with physical access can replace or reflash the EEPROM to run arbitrary code that persists across reboots. Because this design predates modern secure-boot or…

  • CVE-2025-34502HigOct 24, 2025
    risk 0.46cvss epss 0.00

    Deck Mate 2 lacks a verified secure-boot chain and runtime integrity validation for its controller and display modules. Without cryptographic boot verification, an attacker with physical access can modify or replace the bootloader, kernel, or filesystem and gain persistent code…

  • CVE-2025-34500HigOct 24, 2025
    risk 0.46cvss epss 0.00

    Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key shared across devices, and uses a truncated HMAC for integrity validation. Attackers with access to the update interface -…

  • CVE-2025-4106HigOct 24, 2025
    risk 0.58cvss epss 0.00

    An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command.

  • CVE-2025-34293HigOct 24, 2025
    risk 0.56cvss epss 0.00

    GN4 Publishing System versions prior to 2.6 contain an insecure direct object reference (IDOR) vulnerability via the API. Authenticated requests to the API's object endpoints allow an authenticated user to request arbitrary user IDs and receive sensitive account data for those…

  • CVE-2025-60954HigOct 24, 2025
    risk 0.54cvss 8.3epss 0.00

    Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including…

  • CVE-2025-62716HigOct 24, 2025
    risk 0.53cvss 8.1epss 0.00

    Plane is open-source project management software. Prior to version 1.1.0, an open redirect vulnerability in the ?next_path query parameter allows attackers to supply arbitrary schemes (e.g., javascript:) that are passed directly to router.push. This results in a cross-site…

  • CVE-2025-60735HigOct 24, 2025
    risk 0.49cvss 7.6epss 0.00

    PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function

  • CVE-2025-60731HigOct 24, 2025
    risk 0.49cvss 7.6epss 0.00

    PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function

  • CVE-2025-60730HigOct 24, 2025
    risk 0.49cvss 7.6epss 0.00

    PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function

  • CVE-2025-62714HigOct 24, 2025
    risk 0.50cvss epss 0.01

    Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project. Prior to version 0.2.0, there is an authentication bypass vulnerability in the Karmada Dashboard API. The backend API endpoints (e.g., /api/v1/secret,…

  • CVE-2025-60801HigOct 24, 2025
    risk 0.53cvss 8.2epss 0.00

    jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function.

  • CVE-2025-60566HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetMACFilter.

  • CVE-2025-60565HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSchedule.

  • CVE-2025-60564HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetLog.

  • CVE-2025-60563HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetPortTr.

  • CVE-2025-60562HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formWlSiteSurvey.

  • CVE-2025-60561HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEmail.

  • CVE-2025-60559HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetDomainFilter.

  • CVE-2025-60558HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formVirtualServ.

  • CVE-2025-60557HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEasy_Wizard.

  • CVE-2025-60556HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizard1.

  • CVE-2025-60555HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizardSelectMode.

  • CVE-2025-60552HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formTcpipSetup.

  • CVE-2025-60551HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the next_page parameter in the function formDeviceReboot.

  • CVE-2025-60550HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formEasySetTimezone.

  • CVE-2025-60549HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAutoDetecWAN_wizard4.

  • CVE-2025-60547HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWAN_Wizard7.

  • CVE-2025-60938HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.01

    Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands on the target system. The vulnerability stems from insufficient input validation of user-controlled parameters including…

  • CVE-2025-60572HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvNetwork.

  • CVE-2025-60571HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600LAx FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetQoS.

  • CVE-2025-60570HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLogDnsquery.

  • CVE-2025-60569HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetRoute.

  • CVE-2025-60568HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvFirewall.

  • CVE-2025-43994HigOct 24, 2025
    risk 0.56cvss 8.6epss 0.01

    Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

  • CVE-2025-11145HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in CBK Soft Software Hardware Electronic Computer Systems Industry and Trade Inc. EnVision allows Account…

  • CVE-2025-46183HigOct 24, 2025
    risk 0.53cvss 8.2epss 0.00

    The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker provides a specially crafted .ser file, deserialization may result in unintended code execution or other malicious behavior on the target system.

  • CVE-2025-40024HigOct 24, 2025
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: vhost: Take a reference on the task in struct vhost_task. vhost_task_create() creates a task and keeps a reference to its task_struct. That task may exit early via a signal and its task_struct will be…

  • CVE-2025-40018HigOct 24, 2025
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ipvs: Defer ip_vs_ftp unregister during netns cleanup On the netns cleanup path, __ip_vs_ftp_exit() may unregister ip_vs_ftp before connections with valid cp->app pointers are flushed, leading to a…

  • CVE-2025-10861HigOct 24, 2025
    risk 0.42cvss 7.5epss 0.00

    The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.1.4. This is due to insufficient validation on the URLs supplied via…

  • CVE-2023-53733HigOct 24, 2025
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: net: sched: cls_u32: Undo tcf_bind_filter if u32_replace_hw_knode When u32_replace_hw_knode fails, we need to undo the tcf_bind_filter operation done at u32_set_parms.

  • CVE-2025-10680HigOct 24, 2025
    risk 0.58cvss 8.8epss 0.07

    OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use

  • CVE-2025-12028HigOct 24, 2025
    risk 0.50cvss 8.8epss 0.00

    The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4. This is due to missing nonce verification on the `login_form_indieauth()` function and the authorization endpoint at wp-login.php?action=indieauth. This…

  • CVE-2025-11889HigOct 24, 2025
    risk 0.47cvss 7.2epss 0.01

    The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import functionality in all versions up to, and including, 1.3.18. This makes it possible for authenticated attackers, with…

  • CVE-2025-11504HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dupasrala.txt file. This makes it possible for unauthenticated attackers to view the plugin's API key…

  • CVE-2025-62868HigOct 24, 2025
    risk 0.53cvss 8.1epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Edge CPT allows PHP Local File Inclusion.This issue affects Edge CPT: from n/a through 1.4.

  • CVE-2025-62254HigOct 23, 2025
    risk 0.42cvss 7.5epss 0.01

    The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number or…

  • CVE-2025-58429HigOct 23, 2025
    risk 0.49cvss 7.5epss 0.01

    A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and delete arbitrary files on the target machine.

  • CVE-2025-62688HigOct 23, 2025
    risk 0.46cvss 7.1epss 0.00

    An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker with low-privileged credentials to change their role, gaining full control access to the project.