VYPR

CVEs

117,010 total · page 636 of 2,341

  • CVE-2025-47219HigAug 7, 2025
    risk 0.46cvss 8.1epss 0.01

    In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading to information disclosure.

  • CVE-2025-55077HigAug 7, 2025
    risk 0.48cvss 7.4epss 0.00

    Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating system commands within the remote Microsoft Windows environment with the privileges of the authenticated user. Tyler Technologies deployed hardened remote…

  • CVE-2025-50675HigAug 7, 2025
    risk 0.51cvss 7.8epss 0.00

    GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installation directory. The directory is accessible with full read, write, and execute permissions for all users, allowing unprivileged users to manipulate files within…

  • CVE-2025-51629HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Temp parameter.

  • CVE-2023-41532HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorsearch.php.

  • CVE-2023-41531HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and password2 parameters.

  • CVE-2023-41524HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username parameter at index.php.

  • CVE-2023-41523HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress parameter at createClassTeacher.php.

  • CVE-2023-41522HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStudents.php via the Id, firstname, and admissionNumber parameters.

  • CVE-2023-41521HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessionTerm.php via the id, termId, and sessionName parameters.

  • CVE-2023-41520HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassArms.php via the classId and classArmName parameters.

  • CVE-2025-55138HigAug 7, 2025
    risk 0.48cvss 7.4epss 0.00

    LinkJoin through 882f196 mishandles token ownership in password reset.

  • CVE-2025-55137HigAug 7, 2025
    risk 0.48cvss 7.4epss 0.00

    LinkJoin through 882f196 mishandles lacks type checking in password reset.

  • CVE-2025-24000HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Saad Iqbal Post SMTP post-smtp allows Authentication Bypass.This issue affects Post SMTP: from n/a through <= 3.2.0.

  • CVE-2025-47907HigAug 7, 2025
    risk 0.39cvss 7.0epss 0.00

    Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the…

  • CVE-2025-35970HigAug 7, 2025
    risk 0.49cvss 7.5epss 0.00

    On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from the information available via SNMP. If the administrator password is not changed from the initial one, a remote attacker with SNMP access can log in to the…

  • CVE-2025-29866HigAug 7, 2025
    risk 0.57cvss epss 0.00

    : External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This issue affects X-Free Uploader: from 1.0.1.0084 before 1.0.1.0085, from 2.0.1.0034 before 2.0.1.0035.

  • CVE-2025-8578HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2025-8576HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)

  • CVE-2025-29865HigAug 7, 2025
    risk 0.57cvss epss 0.00

    : Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TAGFREE X-Free Uploader XFU allows Path Traversal.This issue affects X-Free Uploader: from 1.0.1.0084 before 1.0.1.0085, from 2.0.1.0034 before 2.0.1.0035.

  • CVE-2025-54882HigAug 7, 2025
    risk 0.00cvss 7.1epss 0.00

    Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1.0.0-beta through 1.1.0, Himmelblau stores the cloud TGT received during logon in the Kerberos credential cache. The created credential cache collection and…

  • CVE-2025-3770HigAug 7, 2025
    risk 0.46cvss 7.0epss 0.00

    EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability.

  • CVE-2025-54788HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execution of queries in the backend database, leading to SQL injection. This can have wide-reaching…

  • CVE-2025-54785HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the unserialize function, which could lead to penetration, privilege…

  • CVE-2025-7770HigAug 6, 2025
    risk 0.57cvss epss 0.01

    Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are generated using a predictable method based on the current timestamp, allowing attackers to recreate valid session IDs. When combined with the ability to circumvent…

  • CVE-2025-7769HigAug 6, 2025
    risk 0.61cvss epss 0.16

    Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due to improper handling of user input. When used with default credentials, this enables attackers to…

  • CVE-2025-6634HigAug 6, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2025-6633HigAug 6, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

  • CVE-2025-51056HigAug 6, 2025
    risk 0.53cvss 8.2epss 0.01

    An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiting the insecure 'uploadPreviews()' custom function in '/api_vedo/colorways_preview', ultimately resulting in remote…

  • CVE-2025-51055HigAug 6, 2025
    risk 0.56cvss 8.6epss 0.00

    Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contains clear-text credentials, secret keys, and database information.

  • CVE-2025-47908HigAug 6, 2025
    risk 0.42cvss 7.5epss 0.01

    Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a Access-Control-Request-Headers (ACRH) header whose value contains many commas. This behavior can be abused by attackers to produce undue load on the…

  • CVE-2025-51624HigAug 6, 2025
    risk 0.49cvss 7.6epss 0.00

    Cross-site scripting (XSS) vulnerability in Zone Bitaqati thru 3.4.0.

  • CVE-2025-46659HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HTTPS request.

  • CVE-2025-45766HigAug 6, 2025
    risk 0.46cvss 7.0epss 0.00

    poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the…

  • CVE-2025-38747HigAug 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to Elevation of Privileges.

  • CVE-2025-53786HigAug 6, 2025
    risk 0.53cvss 8.0epss 0.07

    On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation,…

  • CVE-2025-51532HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Database Monitor via a crafted request. The vendor has stated that the issue is fixed in 2025_06_000, released in June 2025.

  • CVE-2025-51040HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Electrolink FM/DAB/TV Transmitter Web Management System Unauthorized access vulnerability via the /FrameSetCore.html endpoint in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2.

  • CVE-2025-50286HigAug 6, 2025
    risk 0.56cvss 8.1epss 0.09

    A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uploaded, the plugin is automatically extracted and loaded, allowing arbitrary PHP code execution and…

  • CVE-2025-3354HigAug 6, 2025
    risk 0.53cvss 8.1epss 0.00

    IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.

  • CVE-2025-3320HigAug 6, 2025
    risk 0.53cvss 8.1epss 0.00

    IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.

  • CVE-2025-23331HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.01

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a memory allocation with excessive size value, leading to a segmentation fault, by providing an invalid request. A successful exploit of this vulnerability might lead to denial…

  • CVE-2025-23327HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.01

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer overflow through specially crafted inputs. A successful exploit of this vulnerability might lead to denial of service and data tampering.

  • CVE-2025-23326HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer overflow through a specially crafted input. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2025-23325HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause uncontrolled recursion through a specially crafted input. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2025-23324HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overflow or wraparound, leading to a segmentation fault, by providing an invalid request. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2025-23323HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.01

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overflow or wraparound, leading to a segmentation fault, by providing an invalid request. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2025-23322HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.01

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where multiple requests could cause a double free when a stream is cancelled before it is processed. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2025-23321HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a divide by zero issue by issuing an invalid request. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2025-23320HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.01

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause the shared memory limit to be exceeded by sending a very large request. A successful exploit of this vulnerability might lead to information…