VYPR

CVEs

117,273 total · page 591 of 2,346

  • CVE-2025-59814HigSep 25, 2025
    risk 0.57cvss 8.8epss 0.00

    This vulnerability allows malicious actors to gain unauthorized access to the Zenitel ICX500 and ICX510 Gateway Billing Admin endpoint, enabling them to read the entire contents of the Billing Admin database.

  • CVE-2025-57632HigSep 25, 2025
    risk 0.42cvss 7.5epss 0.01

    libsmb2 6.2+ is vulnerable to Buffer Overflow. When processing SMB2 chained PDUs (NextCommand), libsmb2 repeatedly calls smb2_add_iovector() to append to a fixed-size iovec array without checking the upper bound of v->niov (SMB2_MAX_VECTORS=256). An attacker can craft responses…

  • CVE-2025-43993HigSep 25, 2025
    risk 0.51cvss 7.8epss 0.00

    Dell Wireless 5932e and Qualcomm Snapdragon X62 Firmware and GNSS/GPS Driver, versions prior to 3.2.0.22 contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code Execution.

  • CVE-2025-43816HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older…

  • CVE-2025-10967HigSep 25, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in MuFen-mker PHP-Usermm up to 37f2d24e51b04346dfc565b93fc2fc6b37bdaea9. This affects an unknown part of the file /chkuser.php. Performing manipulation of the argument Username results in sql injection. The attack may be initiated remotely. The…

  • CVE-2025-48707HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared among administrators, which can cause secret sharing.

  • CVE-2025-34227HigSep 25, 2025
    risk 0.59cvss 8.8epss 0.24

    Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute…

  • CVE-2025-10880HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the proprietary "Dingtian Binary" protocol password by sending an unauthenticated GET request.

  • CVE-2025-57446HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in O-RAN Near Realtime RIC ric-plt-submgr in the J-Release environment, allows remote attackers to cause a denial of service (DoS) via a crafted request to the Subscription Manager API component.

  • CVE-2025-55560HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.

  • CVE-2025-55559HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.

  • CVE-2025-55558HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a Denial of Service (DoS).

  • CVE-2025-55557HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).

  • CVE-2025-55553HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).

  • CVE-2025-55552HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.

  • CVE-2025-10953HigSep 25, 2025
    risk 0.58cvss 8.8epss 0.05

    A security vulnerability has been detected in UTT 1200GW and 1250GW up to 3.0.0-170831/3.2.2-200710. This vulnerability affects unknown code of the file /goform/formApMail. The manipulation of the argument senderEmail leads to buffer overflow. The attack may be initiated…

  • CVE-2024-48014HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Dell BSAFE Micro Edition Suite, versions prior to 5.0.2.3 contain an Out-of-bounds Write vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2025-59830HigSep 25, 2025
    risk 0.42cvss 7.5epss 0.01

    Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &, while still splitting on both & and ;. As a result, attackers could use ; separators to bypass the parameter count limit and…

  • CVE-2025-55551HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.

  • CVE-2025-40838HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unauthorized disclosure of certain information.

  • CVE-2025-40837HigSep 25, 2025
    risk 0.57cvss 8.8epss 0.00

    Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher privileges than intended.

  • CVE-2025-27262HigSep 25, 2025
    risk 0.51cvss 7.8epss 0.01

    Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation of privileges.

  • CVE-2025-10951HigSep 25, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was identified in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this vulnerability is the function log_handler of the file ml_logger/server.py. Such manipulation of the argument File leads to path traversal. It is possible to launch…

  • CVE-2025-10541HigSep 25, 2025
    risk 0.51cvss 7.8epss 0.00

    iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges. This service includes an insecure update mechanism that automatically loads files placed in the C:\sysupdate\ directory during startup. Because any local user can…

  • CVE-2025-59839HigSep 25, 2025
    risk 0.49cvss 8.6epss 0.00

    The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. In versions 4.0.0 and prior, the EmbedVideo extension allows adding arbitrary attributes to an HTML…

  • CVE-2025-59831HigSep 25, 2025
    risk 0.50cvss 8.8epss 0.02

    git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, there is a command injection vulnerability in git-commiters. This vulnerability manifests with the library's primary exported API: gitCommiters(options,…

  • CVE-2025-57317HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    apidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulnerability in the preProcess function of apidoc-core versions thru 0.15.0 allows attackers to inject properties on Object.prototype via supplying a crafted…

  • CVE-2025-26278HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    A prototype pollution in the lib.set function of dref v0.1.2 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

  • CVE-2025-10948HigSep 25, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip/address/print of the component libjson.so. The manipulation leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2025-10467HigSep 25, 2025
    risk 0.58cvss 8.9epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PROLIZ Computer Software Hardware Service Trade Ltd. Co. OBS (Student Affairs Information System) allows Stored XSS. This issue affects OBS (Student Affairs Information…

  • CVE-2025-10449HigSep 25, 2025
    risk 0.56cvss 8.6epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saysis Computer Systems Trade Ltd. Co. Saysis Web Portal allows Path Traversal. This issue affects Saysis Web Portal: from 3.1.9 & 3.2.0 before 3.2.1.

  • CVE-2025-40698HigSep 25, 2025
    risk 0.57cvss epss 0.00

    SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a POST request using the parameters “mpsCentroin”, “mpsEmpresa”, “mpsProyecto”, and…

  • CVE-2025-10957HigSep 25, 2025
    risk 0.57cvss epss 0.00

    This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. A remote attacker could exploit this vulnerability by establishing an FTP connection using default credentials, potentially gaining unauthorized access to…

  • CVE-2025-10942HigSep 25, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in H3C Magic B3 up to 100R002. This affects the function AddMacList/EditMacList of the file /goform/aspForm. The manipulation of the argument param leads to buffer overflow. The attack can be initiated remotely. The exploit is publicly available…

  • CVE-2025-10941HigSep 25, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was determined in Topaz SERVCore Teller 2.14.0-RC2/2.14.1. Affected by this issue is some unknown functionality of the file SERVCoreTeller_2.0.40D.msi of the component Installer. Executing manipulation can lead to permission issues. The attack needs to be…

  • CVE-2025-10438HigSep 25, 2025
    risk 0.56cvss 8.6epss 0.00

    Path Traversal: 'dir/../../filename' vulnerability in Yordam Information Technology Consulting Education and Electrical Systems Industry Trade Inc. Yordam Katalog allows Path Traversal. This issue affects Yordam Katalog: before 21.7.

  • CVE-2025-54520HigSep 24, 2025
    risk 0.56cvss epss 0.00

    Improper Protection Against Voltage and Clock Glitches in FPGA devices, could allow an attacker with physical access to undervolt the platform resulting in a loss of confidentiality.

  • CVE-2025-59833HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.00

    Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/problems/:id returns challenge hints in plaintext within the question object, regardless of whether the user has unlocked them via point deduction. Users can view…

  • CVE-2025-57319HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.00

    fast-redact is a package that provides do very fast object redaction. A Prototype Pollution vulnerability in the nestedRestore function of fast-redact version 3.5.0 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing…

  • CVE-2025-57318HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.00

    A Prototype Pollution vulnerability in the toCsv function of csvjson versions thru 5.1.0 allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

  • CVE-2025-57329HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.00

    web3-core-method is a package designed to creates the methods on the web3 modules. A Prototype Pollution vulnerability in the attachToObject function of web3-core-method version 1.10.4 and before allows attackers to inject properties on Object.prototype via supplying a crafted…

  • CVE-2025-57328HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.00

    toggle-array is a package designed to enables a property on the object at the specified index, while disabling the property on all other objects. A Prototype Pollution vulnerability in the enable and disable function of toggle-array v1.0.1 and before allows attackers to inject…

  • CVE-2025-57327HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.00

    spmrc is a package that provides the rc manager for spm. A Prototype Pollution vulnerability in the set and config function of spmrc version 1.2.0 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service…

  • CVE-2025-57326HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.00

    A Prototype Pollution vulnerability in the byGroupAndType function of sassdoc-extras v2.5.1 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

  • CVE-2025-57325HigSep 24, 2025
    risk 0.42cvss 7.5epss 0.00

    rollbar is a package designed to effortlessly track and debug errors in JavaScript applications. This package includes advanced error tracking features and an intuitive interface to help you identify and fix issues more quickly. A Prototype Pollution vulnerability in the…

  • CVE-2025-57323HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.00

    mpregular is a package that provides a small program development framework based on RegularJS. A Prototype Pollution vulnerability in the mp.addEventHandler function of mpregular version 0.2.0 and before allows attackers to inject properties on Object.prototype via supplying a…

  • CVE-2025-59251HigSep 24, 2025
    risk 0.49cvss 7.6epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2025-57349HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.00

    The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message key paths in versions prior to 2.3.0. The flaw arises when processing nested message keys containing…

  • CVE-2025-57330HigSep 24, 2025
    risk 0.42cvss 7.5epss 0.00

    The web3-core-subscriptions is a package designed to manages web3 subscriptions. A Prototype Pollution vulnerability in the attachToObject function of web3-core-subscriptions version 1.10.4 and before allows attackers to inject properties on Object.prototype via supplying a…

  • CVE-2025-55322HigSep 24, 2025
    risk 0.47cvss 7.3epss 0.00

    Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.