VYPR

CVEs

116,976 total · page 642 of 2,340

  • CVE-2025-5038HigJul 29, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted X_T file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2025-53715HigJul 29, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/Wan6to4TunnelCfgRpm.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service…

  • CVE-2025-53714HigJul 29, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WzdWlanSiteSurveyRpm_AP.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a…

  • CVE-2025-53713HigJul 29, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_APC.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service…

  • CVE-2025-53712HigJul 29, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_AP.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service…

  • CVE-2025-53711HigJul 29, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been found in TP-Link TL-WR841N v11, TL-WR842ND v2 and TL-WR494N v3. The vulnerability exists in the /userRpm/WlanNetworkRpm.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and…

  • CVE-2025-2928HigJul 29, 2025
    risk 0.47cvss 7.2epss 0.00

    SQL Injection affecting the Archiver role.

  • CVE-2025-44137HigJul 29, 2025
    risk 0.00cvss 8.2epss 0.01

    MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is responsible for delivering tiles that are stored as files on the server via web request. Creating the path to a file allows the insertion of "../" and thus read…

  • CVE-2025-31965HigJul 29, 2025
    risk 0.53cvss 8.2epss 0.00

    Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and lower) allow non-admin users to view unauthorized information on certain web pages.

  • CVE-2025-28170HigJul 29, 2025
    risk 0.49cvss 7.6epss 0.00

    Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files.

  • CVE-2025-51970HigJul 29, 2025
    risk 0.50cvss 7.7epss 0.00

    A SQL Injection vulnerability exists in the action.php endpoint of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter.

  • CVE-2024-42645HigJul 29, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in FlashMQ v1.14.0 allows attackers to cause an assertion failure via sending a crafted retain message, leading to a Denial of Service (DoS).

  • CVE-2024-42644HigJul 29, 2025
    risk 0.49cvss 7.5epss 0.01

    FlashMQ v1.14.0 was discovered to contain an assertion failure in the function PublishCopyFactory::getNewPublish, which occurs when the QoS value of the publish object is greater than 0.

  • CVE-2025-6505HigJul 29, 2025
    risk 0.53cvss 8.1epss 0.00

    Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client impersonation and…

  • CVE-2025-6504HigJul 29, 2025
    risk 0.55cvss 8.4epss 0.00

    In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header.  Since XFF is a client-controlled header, it could be spoofed, allowing unauthorized access if the spoofed IP matched a whitelisted range. This…

  • CVE-2025-6175HigJul 29, 2025
    risk 0.47cvss 7.2epss 0.00

    Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in DECE Software Geodi allows HTTP Request Splitting. This issue affects Geodi: before GEODI Setup 9.0.146.

  • CVE-2025-7689HigJul 29, 2025
    risk 0.50cvss 8.8epss 0.00

    The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tfhb_reset_password_callback() function in versions 1.1.0 to 1.1.18. This makes it possible for authenticated attackers, with Subscriber-level access and above,…

  • CVE-2025-6495HigJul 29, 2025
    risk 0.49cvss 7.5epss 0.00

    The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and including, 1.12.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

  • CVE-2025-53080HigJul 29, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers to create arbitrary files in unintended locations on the filesystem

  • CVE-2025-53078HigJul 29, 2025
    risk 0.52cvss 8.0epss 0.00

    Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system

  • CVE-2025-54769HigJul 29, 2025
    risk 0.60cvss 8.8epss 0.03

    An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an…

  • CVE-2025-50486HigJul 28, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allows attackers to execute a session hijacking attack.

  • CVE-2025-50485HigJul 28, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 allows attackers to execute a session hijacking attack.

  • CVE-2025-29534HigJul 28, 2025
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker with valid credentials to execute arbitrary commands with root privileges. The issue stems from insufficient sanitization of user-supplied input in the…

  • CVE-2025-8194HigJul 28, 2025
    risk 0.42cvss 7.5epss 0.01

    There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of…

  • CVE-2025-50487HigJul 28, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management System v2.4 allows attackers to execute a session hijacking attack.

  • CVE-2025-50484HigJul 28, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session hijacking attack.

  • CVE-2025-50492HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allows attackers to execute a session hijacking attack.

  • CVE-2025-50491HigJul 28, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack.

  • CVE-2025-50489HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.

  • CVE-2025-50488HigJul 28, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management System v3.0 allows attackers to execute a session hijacking attack.

  • CVE-2025-54531HigJul 28, 2025
    risk 0.50cvss 7.7epss 0.00

    In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows

  • CVE-2025-54530HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions

  • CVE-2025-50494HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execute a session hijacking attack.

  • CVE-2025-50493HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management System v1 allows attackers to execute a session hijacking attack.

  • CVE-2025-50490HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.

  • CVE-2025-2297HigJul 28, 2025
    risk 0.51cvss 7.8epss 0.00

    Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their…

  • CVE-2024-49342HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

  • CVE-2025-8279HigJul 28, 2025
    risk 0.57cvss 8.7epss 0.00

    Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution

  • CVE-2025-4056HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in GLib. A denial of service on Windows platforms may occur if an application attempts to spawn a program using long command lines.

  • CVE-2025-8274HigJul 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=save_recruitment_status. The manipulation of the argument ID leads to sql…

  • CVE-2025-5997HigJul 28, 2025
    risk 0.57cvss 8.8epss 0.00

    Incorrect Use of Privileged APIs vulnerability in Beamsec PhishPro allows Privilege Abuse. This issue affects PhishPro: before 7.5.4.2.

  • CVE-2025-38497HigJul 28, 2025
    risk 0.46cvss 7.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: Fix OOB read on empty string write When writing an empty string to either 'qw_sign' or 'landingPage' sysfs attributes, the store functions attempt to access page[l - 1] before validating…

  • CVE-2025-38495HigJul 28, 2025
    risk 0.57cvss 8.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: HID: core: ensure the allocated report buffer can contain the reserved report ID When the report ID is not used, the low level transport drivers expect the first byte to be 0. However, currently the allocated…

  • CVE-2025-38494HigJul 28, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: HID: core: do not bypass hid_hw_raw_request hid_hw_raw_request() is actually useful to ensure the provided buffer and length are valid. Directly calling in the low level transport driver function bypassed…

  • CVE-2025-38491HigJul 28, 2025
    risk 0.53cvss 8.2epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: mptcp: make fallback action and fallback decision atomic Syzkaller reported the following splat: WARNING: CPU: 1 PID: 7704 at net/mptcp/protocol.h:1223 __mptcp_do_fallback net/mptcp/protocol.h:1223 [inline]…

  • CVE-2025-38486HigJul 28, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: soundwire: Revert "soundwire: qcom: Add set_channel_map api support" This reverts commit 7796c97df6b1b2206681a07f3c80f6023a6593d5. This patch broke Dragonboard 845c (sdm845). I see: Unexpected kernel BRK…

  • CVE-2025-38485HigJul 28, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush fxls8962af_fifo_flush() uses indio_dev->active_scan_mask (with iio_for_each_active_channel()) without making sure the indio_dev stays in…

  • CVE-2025-38484HigJul 28, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: iio: backend: fix out-of-bound write The buffer is set to 80 character. If a caller write more characters, count is truncated to the max available space in "simple_write_to_buffer". But afterwards a string…

  • CVE-2025-38483HigJul 28, 2025
    risk 0.46cvss 7.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: comedi: das16m1: Fix bit shift out of bounds When checking for a supported IRQ number, the following test is used: /* only irqs 2, 3, 4, 5, 6, 7, 10, 11, 12, 14, and 15 are valid */ if ((1 <<…