VYPR

CVEs

116,990 total · page 637 of 2,340

  • CVE-2025-21474HigAug 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing commands from A2dp sink command queue.

  • CVE-2025-21473HigAug 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when using Virtual cdm (Camera Data Mover) to write registers.

  • CVE-2025-21461HigAug 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when programming registers through virtual CDM.

  • CVE-2025-21458HigAug 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when IOCTL interface is called to map and unmap buffers simultaneously.

  • CVE-2025-21456HigAug 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.

  • CVE-2025-21455HigAug 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while submitting blob data to kernel space though IOCTL.

  • CVE-2025-21452HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.

  • CVE-2025-8420HigAug 6, 2025
    risk 0.46cvss 8.1epss 0.01

    Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a…

  • CVE-2025-54634HigAug 6, 2025
    risk 0.52cvss 8.0epss 0.00

    Vulnerability of improper processing of abnormal conditions in huge page separation. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-54627HigAug 6, 2025
    risk 0.57cvss 8.8epss 0.00

    Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-8654HigAug 6, 2025
    risk 0.57cvss 8.8epss 0.01

    Kenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this…

  • CVE-2025-8653HigAug 6, 2025
    risk 0.57cvss 8.8epss 0.00

    Kenwood DMX958XR JKRadioService Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Kenwood DMX958XR. Authentication is not required to exploit this…

  • CVE-2025-7036HigAug 6, 2025
    risk 0.42cvss 7.5epss 0.01

    The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all versions up to, and including, 1.5.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

  • CVE-2025-54622HigAug 6, 2025
    risk 0.54cvss 8.3epss 0.00

    Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-54611HigAug 6, 2025
    risk 0.47cvss 7.3epss 0.00

    EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-54607HigAug 6, 2025
    risk 0.50cvss 7.7epss 0.00

    Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-54606HigAug 6, 2025
    risk 0.47cvss 7.3epss 0.00

    Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

  • CVE-2025-54655HigAug 6, 2025
    risk 0.53cvss 8.1epss 0.00

    Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality and integrity of the virtualization graphics module.

  • CVE-2025-54653HigAug 6, 2025
    risk 0.55cvss 8.4epss 0.00

    Path traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect the confidentiality of the virtualization file module.

  • CVE-2025-54652HigAug 6, 2025
    risk 0.55cvss 8.4epss 0.00

    Path traversal vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality of the virtualization module.

  • CVE-2025-54884HigAug 6, 2025
    risk 0.50cvss epss 0.00

    Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the generateSecureId and getSecureRandomInt functions in security-kit versions prior to 3.5.0 (packaged in Vision UI 1.4.0 and below) are vulnerable to…

  • CVE-2025-54872HigAug 6, 2025
    risk 0.50cvss epss 0.00

    onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd89 contain a baked-in tor image if the secrets were copied from an existing onion domain. A website could be compromised if a user shared the baked-in image,…

  • CVE-2025-54801HigAug 6, 2025
    risk 0.42cvss 7.5epss 0.00

    Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g., test.18446744073704), the application crashes due to an out-of-bounds…

  • CVE-2025-53534HigAug 5, 2025
    risk 0.43cvss epss 0.01

    RatPanel is a server operation and maintenance management panel. In versions 2.3.19 through 2.5.5, when an attacker obtains the backend login path of RatPanel (including but not limited to weak default paths, brute-force cracking, etc.), they can execute system commands or take…

  • CVE-2013-10065HigAug 5, 2025
    risk 0.52cvss 7.5epss 0.01

    A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH key exchange packet can trigger a crash in the service, resulting in loss of availability. The flaw is triggered during the handling of malformed key exchange…

  • CVE-2012-10034HigAug 5, 2025
    risk 0.52cvss 7.5epss 0.01

    ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of the cs_lang cookie parameter. The application fails to sanitize user-supplied input, allowing attackers to traverse directories and read arbitrary files outside the web root. The…

  • CVE-2012-10032HigAug 5, 2025
    risk 0.60cvss epss 0.01

    Maxthon3 version 3.2.2 build 1000 and prior are vulnerable to cross context scripting (XCS) via the about:history page. The browser’s trusted zone improperly handles injected script content, allowing attackers to execute arbitrary JavaScript in a privileged context. This flaw…

  • CVE-2012-10031HigAug 5, 2025
    risk 0.59cvss epss 0.01

    BlazeVideo HDTV Player Pro v6.6.0.3 is vulnerable to a stack-based buffer overflow due to improper handling of user-supplied input embedded in .plf playlist files. When parsing a crafted .plf file, the MediaPlayerCtrl.dll component invokes PathFindFileNameA() to extract a…

  • CVE-2012-10029HigAug 5, 2025
    risk 0.59cvss epss 0.03

    Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code execution.

  • CVE-2012-10028HigAug 5, 2025
    risk 0.59cvss epss 0.01

    Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows authenticated users to execute arbitrary system commands via crafted POST requests to `surgeftpmgr.cgi`. This can lead to full remote code execution on the…

  • CVE-2012-10024HigAug 5, 2025
    risk 0.42cvss epss 0.01

    XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authenticated users to request files outside the intended document root. An attacker can…

  • CVE-2025-51628HigAug 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa Eccobook v2.81.1 and below allows unauthenticated attackers to read confidential documents via the DocumentoId parameter.

  • CVE-2025-7674HigAug 5, 2025
    risk 0.46cvss epss 0.00

    Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker to manipulate input data, which may lead to a denial of service (DoS) due to negatively impacting the server's performance. This vulnerability has no impact on data confidentiality…

  • CVE-2025-54254HigAug 5, 2025
    risk 0.63cvss 8.6epss 0.77

    Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local…

  • CVE-2025-43978HigAug 5, 2025
    risk 0.48cvss 7.4epss 0.01

    Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vulnerable, including /ubus/?flag=set_WPS_pin and /ubus/?flag=netAppStar1 and /ubus/?flag=set_wifi_cfgs. This allows an authenticated attacker to execute…

  • CVE-2025-43979HigAug 5, 2025
    risk 0.48cvss 7.4epss 0.06

    An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated attackers to execute arbitrary OS system commands with root privileges via crafted payloads to the xml_action.cgi?method= endpoint.

  • CVE-2025-29745HigAug 5, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote server to obtain Net-NTLMv2 hash information via a specially created A2S (Emsisoft Custom Scan) extension file.

  • CVE-2025-7033HigAug 5, 2025
    risk 0.51cvss 7.8epss 0.00

    A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute…

  • CVE-2025-7032HigAug 5, 2025
    risk 0.51cvss 7.8epss 0.00

    A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute…

  • CVE-2025-7025HigAug 5, 2025
    risk 0.51cvss 7.8epss 0.00

    A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute…

  • CVE-2025-6207HigAug 5, 2025
    risk 0.49cvss 7.5epss 0.01

    The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up to, and including, 3.9.28. This makes it possible for authenticated attackers, with…

  • CVE-2025-5061HigAug 5, 2025
    risk 0.49cvss 7.5epss 0.01

    The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' function in all versions up to, and including, 3.9.29. This makes it possible for authenticated attackers, with…

  • CVE-2025-41698HigAug 5, 2025
    risk 0.51cvss 7.8epss 0.00

    A low privileged local attacker can interact with the affected service although user-interaction should not be allowed.

  • CVE-2025-7050HigAug 5, 2025
    risk 0.47cvss 7.2epss 0.00

    The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in file metadata in all versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes…

  • CVE-2025-54868HigAug 5, 2025
    risk 0.00cvss 7.5epss 0.00

    LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint allows reading arbitrary chats directly from the Meilisearch engine. The endpoint /api/search/test allows for direct access to stored chats in the Meilisearch…

  • CVE-2025-54870HigAug 5, 2025
    risk 0.50cvss epss 0.00

    VTun-ng is a Virtual Tunnel over TCP/IP network. In versions 3.0.17 and below, failure to initialize encryption modules might cause reversion to plaintext due to insufficient error handling. The bug was first introduced in VTun-ng version 3.0.12. This is fixed in version 3.0.18.…

  • CVE-2025-54865HigAug 5, 2025
    risk 0.47cvss 7.3epss 0.00

    Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query executed by the Tilesheets extension allows users to insert and potentially execute malicious SQL code. This issue has not been fixed.

  • CVE-2025-54803HigAug 5, 2025
    risk 0.42cvss 7.5epss 0.01

    js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. In versions below 1.0.2, a prototype pollution vulnerability in js-toml allows a remote attacker to add or modify properties of the global Object.prototype by parsing a maliciously crafted TOML…

  • CVE-2025-54780HigAug 5, 2025
    risk 0.43cvss 7.7epss 0.00

    The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2.0.2, authenticated user can use the /ajax/screenshot.php endpoint to leak files from the system or use PHP wrappers. This is fixed in version 2.0.2.

  • CVE-2025-54135HigAug 5, 2025
    risk 0.55cvss 8.5epss 0.02

    Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the file is a dotfile, editing it requires approval but creating a new one doesn't. Hence, if sensitive MCP files, such as the…