VYPR

CVEs

117,303 total · page 580 of 2,347

  • CVE-2025-47349HigOct 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing an escape call.

  • CVE-2025-47347HigOct 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing control commands in the virtual memory management interface.

  • CVE-2025-47342HigOct 9, 2025
    risk 0.46cvss 7.1epss 0.00

    Transient DOS may occur when multi-profile concurrency arises with QHS enabled.

  • CVE-2025-47341HigOct 9, 2025
    risk 0.51cvss 7.8epss 0.00

    memory corruption while processing an image encoding completion event.

  • CVE-2025-47340HigOct 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing IOCTL call to get the mapping.

  • CVE-2025-47338HigOct 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing escape commands from userspace.

  • CVE-2025-27060HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.00

    Memory corruption while performing SCM call with malformed inputs.

  • CVE-2025-27059HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.00

    Memory corruption while performing SCM call.

  • CVE-2025-27054HigOct 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing a malformed license file during reboot.

  • CVE-2025-27053HigOct 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption during PlayReady APP usecase while processing TA commands.

  • CVE-2025-27048HigOct 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing camera platform driver IOCTL calls.

  • CVE-2025-11529HigOct 9, 2025
    risk 0.40cvss 7.3epss 0.01

    A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/ChurchCRM/Slim/Middleware/AuthMiddleware.php of the component API Endpoint. The manipulation results in missing authentication. The attack can be executed…

  • CVE-2025-11528HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/saveAutoQos. The manipulation of the argument enable leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly…

  • CVE-2025-11527HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in Tenda AC7 15.03.06.44. The impacted element is an unknown function of the file /goform/fast_setting_pppoe_set. Executing a manipulation of the argument Password can lead to stack-based buffer overflow. The attack may be launched remotely. The…

  • CVE-2025-11526HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda AC7 15.03.06.44. The affected element is an unknown function of the file /goform/WifiMacFilterSet. Performing a manipulation of the argument wifi_chkHz results in stack-based buffer overflow. The attack may be initiated remotely. The exploit…

  • CVE-2025-11525HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Tenda AC7 15.03.06.44. Impacted is an unknown function of the file /goform/SetUpnpCfg. Such manipulation of the argument upnpEn leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the…

  • CVE-2025-11524HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.01

    A flaw has been found in Tenda AC7 15.03.06.44. This issue affects some unknown processing of the file /goform/SetDDNSCfg. This manipulation of the argument ddnsEn causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be…

  • CVE-2025-10496HigOct 9, 2025
    risk 0.47cvss 7.2epss 0.00

    The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uuid parameter in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2025-11513HigOct 9, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in code-projects E-Commerce Website 1.0. This affects an unknown part of the file /pages/supplier_update.php. This manipulation of the argument supp_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2025-11535HigOct 8, 2025
    risk 0.57cvss epss 0.00

    MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.14.24.

  • CVE-2025-11507HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /admin/search-invoices.php. This manipulation of the argument searchdata causes sql injection. The attack can be initiated remotely. The…

  • CVE-2025-11506HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown function of the file /admin/search-appointment.php. The manipulation of the argument searchdata results in sql injection. It is possible to launch the…

  • CVE-2025-11505HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function of the file /admin/new-appointment.php. The manipulation of the argument delid leads to sql injection. It is possible to initiate the attack remotely. The exploit…

  • CVE-2025-60311HigOct 8, 2025
    risk 0.57cvss 8.8epss 0.00

    ProjectWorlds Gym Management System1.0 is vulnerable to SQL Injection via the "id" parameter in the profile/edit.php page

  • CVE-2025-11503HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in PHPGurukul Beauty Parlour Management System 1.1. This issue affects some unknown processing of the file /admin/manage-services.php. Executing a manipulation of the argument delid can lead to sql injection. The attack may be performed from…

  • CVE-2025-61524HigOct 8, 2025
    risk 0.40cvss 7.2epss 0.01

    An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.2.63.0, allows remote authenticated administrators of any organization within the system to bypass the system's permission verification…

  • CVE-2025-57457HigOct 8, 2025
    risk 0.57cvss 8.8epss 0.01

    An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS Commands via the "IP Addr" parameter.

  • CVE-2025-9868HigOct 8, 2025
    risk 0.57cvss epss 0.00

    Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.

  • CVE-2025-11488HigOct 8, 2025
    risk 0.48cvss 7.3epss 0.02

    A weakness has been identified in D-Link DIR-852 up to 20251002. This affects an unknown part of the file /HNAP1/. Executing manipulation can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be exploited.…

  • CVE-2025-9970HigOct 8, 2025
    risk 0.48cvss 7.4epss 0.00

    Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects MConfig: through 1.4.9.21.

  • CVE-2025-53967HigOct 8, 2025
    risk 0.46cvss 8.0epss 0.07

    Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metacharacters in input that is used by a fetchWithRetry curl command. The vulnerable endpoint fails to…

  • CVE-2025-11480HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in SourceCodester Simple E-Commerce Bookstore 1.0. The affected element is an unknown function of the file /register.php. Performing manipulation of the argument register_username results in sql injection. The attack is possible to be carried out…

  • CVE-2025-11479HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in SourceCodester Wedding Reservation Management System 1.0. Impacted is the function insertReservation of the file function.php. Such manipulation of the argument number leads to sql injection. The attack can be executed remotely. The…

  • CVE-2025-11477HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in SourceCodester Wedding Reservation Management System 1.0. This vulnerability affects unknown code of the file /global.php. The manipulation of the argument User results in sql injection. The attack may be launched remotely. The exploit has…

  • CVE-2025-11476HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in SourceCodester Simple E-Commerce Bookstore 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument login_username leads to sql injection. The attack may be initiated remotely. The exploit is publicly available…

  • CVE-2025-11475HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /view_member.php. Executing a manipulation of the argument user_id can lead to sql injection. The attack can be launched…

  • CVE-2025-11473HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected is an unknown function of the file /edit_curr.php. Such manipulation of the argument currsymbol leads to sql injection. It is possible to launch the attack remotely. The exploit has…

  • CVE-2025-11472HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in SourceCodester Hotel and Lodge Management System 1.0. This impacts an unknown function of the file /edit_room.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published…

  • CVE-2025-11471HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in SourceCodester Hotel and Lodge Management System 1.0. This affects an unknown function of the file /edit_customer.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public…

  • CVE-2025-11444HigOct 8, 2025
    risk 0.57cvss 8.8epss 0.01

    A security vulnerability has been detected in TOTOLINK N600R up to 4.3.0cu.7866_B20220506. This impacts the function setWiFiBasicConfig of the file /cgi-bin/cstecgi.cgi of the component HTTP Request Handler. Such manipulation of the argument wepkey leads to buffer overflow. It…

  • CVE-2025-10635HigOct 8, 2025
    risk 0.50cvss 7.7epss 0.00

    The Find Me On WordPress plugin through 2.0.9.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers and above to perform SQL injection attacks

  • CVE-2025-11434HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in itsourcecode Student Transcript Processing System 1.0. Affected is an unknown function of the file /login.php. Executing a manipulation of the argument uname can lead to sql injection. It is possible to launch the attack remotely. The exploit…

  • CVE-2025-11432HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /reset.php. Such manipulation of the argument employid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and…

  • CVE-2025-11204HigOct 8, 2025
    risk 0.40cvss 7.2epss 0.00

    The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.0.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2025-11430HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in SourceCodester Simple E-Commerce Bookstore 1.0. The affected element is an unknown function of the file /cart.php. The manipulation of the argument remove results in sql injection. The attack can be executed remotely. The exploit has been made public…

  • CVE-2025-10494HigOct 8, 2025
    risk 0.53cvss 8.1epss 0.00

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation when deleting profile pictures in all versions up to, and including, 1.4.89. This makes it possible for authenticated…

  • CVE-2025-61787HigOct 8, 2025
    risk 0.46cvss 8.1epss 0.02

    Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, ``CreateProcess()`` always implicitly spawns ``cmd.exe`` if a batch file (.bat,…

  • CVE-2025-11424HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in code-projects Web-Based Inventory and POS System 1.0. This impacts an unknown function of the file /login.php. Executing manipulation of the argument emailid can lead to sql injection. The attack may be performed from remote. The exploit has…

  • CVE-2025-11422HigOct 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Campcodes Advanced Online Voting Management System 1.0. The impacted element is an unknown function of the file /admin/login.php. Such manipulation of the argument Username leads to sql injection. The attack can be executed remotely. The exploit…

  • CVE-2025-48981HigOct 8, 2025
    risk 0.56cvss 8.6epss 0.00

    An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate data on the protocol because encryption is optional for this connection.