VYPR

CVEs

117,078 total · page 620 of 2,342

  • CVE-2025-43960HigAug 25, 2025
    risk 0.56cvss 8.6epss 0.01

    Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious…

  • CVE-2025-29516HigAug 25, 2025
    risk 0.47cvss 7.2epss 0.02

    D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the backup function.

  • CVE-2025-26467HigAug 25, 2025
    risk 0.57cvss 8.8epss 0.01

    Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting data MODIFY permission on…

  • CVE-2023-47799HigAug 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files are given to the account holders. They may contain images of other account…

  • CVE-2025-5191HigAug 25, 2025
    risk 0.47cvss epss 0.00

    An Unquoted Search Path vulnerability has been identified in the utility for Moxa’s industrial computers (Windows). Due to the unquoted path configuration in the SerialInterfaceService.exe utility, a local attacker with limited privileges could place a malicious executable in…

  • CVE-2025-54301HigAug 25, 2025
    risk 0.55cvss epss 0.00

    A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. File names are not properly escaped.

  • CVE-2025-54300HigAug 25, 2025
    risk 0.55cvss epss 0.00

    A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. The SVG upload feature does not sanitize uploads.

  • CVE-2025-9393HigAug 24, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function addStaProfile of the file /goform/addStaProfile. Performing manipulation of the argument…

  • CVE-2025-9392HigAug 24, 2025
    risk 0.57cvss 8.8epss 0.04

    A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function qosClassifier of the file /goform/qosClassifier. Such manipulation of the argument…

  • CVE-2025-9380HigAug 24, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was identified in FNKvision Y215 CCTV Camera 10.194.120.40. Affected by this issue is some unknown functionality of the file /etc/passwd of the component Firmware. Such manipulation leads to hard-coded credentials. Local access is required to approach this…

  • CVE-2025-9379HigAug 24, 2025
    risk 0.47cvss 7.2epss 0.00

    A vulnerability was determined in Belkin AX1800 1.1.00.016. Affected by this vulnerability is an unknown functionality of the component Firmware Update Handler. This manipulation causes insufficient verification of data authenticity. The attack can be initiated remotely. The…

  • CVE-2025-36174HigAug 24, 2025
    risk 0.52cvss 8.0epss 0.00

    IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if opened.

  • CVE-2025-9363HigAug 23, 2025
    risk 0.57cvss 8.8epss 0.04

    A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function portTriggerManageRule of the file /goform/portTriggerManageRule. The manipulation of the argument…

  • CVE-2025-9361HigAug 23, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The affected element is the function ipRangeBlockManageRule of the file /goform/ipRangeBlockManageRule. Performing manipulation of…

  • CVE-2025-9360HigAug 23, 2025
    risk 0.57cvss 8.8epss 0.01

    A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Impacted is the function accessControlAdd of the file /goform/accessControlAdd. Such manipulation of the argument…

  • CVE-2025-9359HigAug 23, 2025
    risk 0.57cvss 8.8epss 0.01

    A weakness has been identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function RP_checkCredentialsByBBS of the file /goform/RP_checkCredentialsByBBS. This manipulation of the…

  • CVE-2025-9358HigAug 23, 2025
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function setSysAdm of the file /goform/setSysAdm. The manipulation of the argument admpasshint…

  • CVE-2025-5060HigAug 23, 2025
    risk 0.53cvss 8.1epss 0.00

    The Bravis User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly logging a user in with the data that was previously verified through the facebook_ajax_login_callback(). This makes it…

  • CVE-2025-9357HigAug 23, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function langSwitchByBBS of the file /goform/langSwitchByBBS. The manipulation of the argument langSelectionOnly…

  • CVE-2025-7813HigAug 23, 2025
    risk 0.40cvss 7.2epss 0.00

    The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxy_image function. This makes it possible for unauthenticated attackers to…

  • CVE-2025-9048HigAug 23, 2025
    risk 0.53cvss 8.1epss 0.01

    The Wptobe-memberships plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the del_img_ajax_call() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with…

  • CVE-2025-43768HigAug 23, 2025
    risk 0.43cvss 7.7epss 0.00

    Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows authenticated users without any permissions to access sensitive…

  • CVE-2025-9356HigAug 22, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this issue is the function inboundFilterAdd of the file /goform/inboundFilterAdd. Executing manipulation of the…

  • CVE-2025-9355HigAug 22, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this vulnerability is the function scheduleAdd of the file /goform/scheduleAdd. Performing manipulation of the argument…

  • CVE-2025-52451HigAug 22, 2025
    risk 0.55cvss 8.5epss 0.00

    Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) allows Absolute Path Traversal.This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

  • CVE-2025-26498HigAug 22, 2025
    risk 0.47cvss 7.3epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-connection-no-undo modules) allows Absolute Path Traversal.This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

  • CVE-2025-26497HigAug 22, 2025
    risk 0.47cvss 7.3epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Absolute Path Traversal.This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

  • CVE-2025-6791HigAug 22, 2025
    risk 0.57cvss 8.8epss 0.00

    In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon web (Monitoring event logs modules)…

  • CVE-2025-55454HigAug 22, 2025
    risk 0.57cvss 8.8epss 0.01

    An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask v1.0.51 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2025-54813HigAug 22, 2025
    risk 0.00cvss 7.5epss 0.01

    Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes are properly escaped. If an attacker-supplied message contains certain non-printable characters, these will be passed along in the message and written out as…

  • CVE-2025-4650HigAug 22, 2025
    risk 0.47cvss 7.2epss 0.00

    User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutralization of Special Elements used in an SQL Command.This issue affects web: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before…

  • CVE-2024-48988HigAug 22, 2025
    risk 0.42cvss 7.6epss 0.01

    SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. This vulnerability is present only in the distribution package (SpringBoot platform) and…

  • CVE-2025-55581HigAug 22, 2025
    risk 0.47cvss 7.3epss 0.00

    D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. The script monitors and respawns the `dcp` and `signalc` binaries without validating their integrity, origin, or permissions. An attacker…

  • CVE-2025-52287HigAug 22, 2025
    risk 0.57cvss 8.8epss 0.01

    OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.

  • CVE-2025-52085HigAug 22, 2025
    risk 0.57cvss 8.8epss 0.01

    An SQL injection vulnerability in Yoosee application v6.32.4 allows authenticated users to inject arbitrary SQL queries via a request to a backend API endpoint. Successful exploitation enables extraction of sensitive database information, including but not limited to, the…

  • CVE-2025-57800HigAug 22, 2025
    risk 0.00cvss 8.8epss 0.00

    Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect callback URLs during OIDC authentication. An attacker can craft a login link that causes Audiobookshelf to store an arbitrary…

  • CVE-2025-57771HigAug 22, 2025
    risk 0.46cvss 8.1epss 0.01

    Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions prior to 3.25.5, Roo-Code fails to properly handle process substitution and single ampersand characters in the command parsing logic for auto-execute commands. If a user has enabled…

  • CVE-2025-55745HigAug 22, 2025
    risk 0.50cvss 8.8epss 0.01

    UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and prior are vulnerable to CSV injection, also known as formula injection, in the Quick Export feature. This vulnerability allows attackers to inject malicious…

  • CVE-2025-55634HigAug 22, 2025
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows unauthorized attackers to cause a Denial of Service (DoS) via initiating a large number of simultaneous ffmpeg-based stream…

  • CVE-2025-55630HigAug 22, 2025
    risk 0.47cvss 7.3epss 0.00

    A discrepancy in the error message returned by the login function of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 when entering the wrong username and password allows attackers to enumerate existing accounts.

  • CVE-2024-53494HigAug 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive components without authentication.

  • CVE-2025-55741HigAug 22, 2025
    risk 0.46cvss 8.1epss 0.00

    UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 and earlier, users without the Delete privilege for products are unable to delete individual products via the standard endpoint, as expected. However, these…

  • CVE-2025-55611HigAug 22, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formLanguageChange function via the nextPage parameter.

  • CVE-2025-55606HigAug 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromAdvSetMacMtuWan function via the serverName parameter.

  • CVE-2025-55605HigAug 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the saveParentControlInfo function via the deviceName parameter.

  • CVE-2025-55603HigAug 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromSetSysTime function via the ntpServer parameter.

  • CVE-2025-55602HigAug 22, 2025
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formSysCmd function via the submit-url parameter.

  • CVE-2025-55599HigAug 22, 2025
    risk 0.49cvss 7.5epss 0.00

    D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formWlanSetup function via the parameter f_wds_wepKey.

  • CVE-2025-52094HigAug 22, 2025
    risk 0.51cvss 7.8epss 0.00

    Insecure Permissions vulnerability in PDQ Smart Deploy V.3.0.2040 allows a local attacker to execute arbtirary code via the \HKLM\SYSTEM\Setup\SmartDeploy component

  • CVE-2025-51605HigAug 22, 2025
    risk 0.53cvss 8.1epss 0.00

    An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client-supplied Origin header verbatim into Access-Control-Allow-Origin without any whitelist validation, while also enabling Access-Control-Allow-Credentials: true. This allows any…