VYPR

CVEs

116,958 total · page 651 of 2,340

  • CVE-2025-54313HigKEVJul 19, 2025
    risk 0.54cvss 7.5epss 0.04

    eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

  • CVE-2025-7833HigJul 19, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issue affects some unknown processing of the file /members/giving.php. The manipulation of the argument Amount leads to sql injection. The attack may be initiated…

  • CVE-2025-7832HigJul 19, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical was found in code-projects Church Donation System 1.0. This vulnerability affects unknown code of the file /members/offering.php. The manipulation of the argument trcode leads to sql injection. The attack can be initiated remotely. The…

  • CVE-2025-7831HigJul 19, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical has been found in code-projects Church Donation System 1.0. This affects an unknown part of the file /members/Tithes.php. The manipulation of the argument trcode leads to sql injection. It is possible to initiate the attack remotely. The…

  • CVE-2025-7830HigJul 19, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /reg.php. The manipulation of the argument mobile leads to sql injection. The attack may be launched remotely.…

  • CVE-2025-7829HigJul 19, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack can be…

  • CVE-2025-7824HigJul 19, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. This issue affects some unknown processing of the file XmlHttp.aspx. The manipulation leads to xml external entity reference. The attack may be initiated remotely. The exploit has been disclosed to the…

  • CVE-2025-7823HigJul 19, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code of the file ProjectScheduleDelete.aspx. The manipulation leads to xml external entity reference. The attack can be initiated remotely. The exploit has been…

  • CVE-2015-10139HigJul 19, 2025
    risk 0.60cvss 8.8epss 0.01

    The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin…

  • CVE-2015-10136HigJul 19, 2025
    risk 0.45cvss 7.5epss 0.02

    The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

  • CVE-2015-10134HigJul 19, 2025
    risk 0.52cvss 7.5epss 0.01

    The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download…

  • CVE-2015-10133HigJul 19, 2025
    risk 0.50cvss 7.2epss 0.01

    The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 via the Path to header value. This allows authenticated attackers, with administrative privileges and above, to include and execute arbitrary files on the…

  • CVE-2025-38350HigJul 19, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: net/sched: Always pass notifications when child class becomes empty Certain classful qdiscs may invoke their classes' dequeue handler on an enqueue operation. This may unexpectedly empty the child qdisc and…

  • CVE-2025-27210HigJul 18, 2025
    risk 0.53cvss 7.5epss 0.15

    An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API.

  • CVE-2025-27209HigJul 18, 2025
    risk 0.49cvss 7.5epss 0.01

    The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability as an attacker who can control the strings to be hashed can generate many hash collisions - an attacker can generate…

  • CVE-2025-7814HigJul 18, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical was found in code-projects Food Ordering Review System 1.0. This vulnerability affects unknown code of the file /pages/signup_function.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely.…

  • CVE-2025-7807HigJul 18, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. This issue affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. The manipulation of the argument Go/page leads to stack-based buffer overflow. The attack may be…

  • CVE-2025-7806HigJul 18, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. This vulnerability affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. The manipulation of the argument Go/page leads to stack-based buffer overflow. The attack can be initiated…

  • CVE-2025-7805HigJul 18, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromPptpUserSetting of the file /goform/PPTPUserSetting. The manipulation of the argument delno leads to stack-based buffer overflow. It is possible to initiate the attack…

  • CVE-2025-50708HigJul 18, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in Perplexity AI GPT-4 v.2.51.0 allows a remote attacker to obtain sensitive information via the token component in the shared chat URL

  • CVE-2025-7801HigJul 18, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in BossSoft CRM 6.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /crm/module/HNDCBas_customPrmSearchDtl.jsp. The manipulation of the argument cstid leads to sql injection. The attack can be…

  • CVE-2025-52169HigJul 18, 2025
    risk 0.46cvss 7.1epss 0.00

    agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.

  • CVE-2025-50585HigJul 18, 2025
    risk 0.57cvss 8.8epss 0.00

    StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl.

  • CVE-2025-7796HigJul 18, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, was found in Tenda FH451 1.0.0.9. This affects the function fromPptpUserAdd of the file /goform/PPTPDClient. The manipulation of the argument Username leads to stack-based buffer overflow. It is possible to initiate the attack…

  • CVE-2025-7795HigJul 18, 2025
    risk 0.60cvss 8.8epss 0.03

    A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be…

  • CVE-2025-52164HigJul 18, 2025
    risk 0.53cvss 8.2epss 0.00

    Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to store credentials in plaintext.

  • CVE-2025-7794HigJul 18, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be…

  • CVE-2025-7793HigJul 18, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function formWebTypeLibrary of the file /goform/webtypelibrary. The manipulation of the argument webSiteId leads to stack-based buffer overflow. It is possible to launch the attack…

  • CVE-2025-7792HigJul 18, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda FH451 1.0.0.9. It has been rated as critical. This issue affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated…

  • CVE-2025-53762HigJul 18, 2025
    risk 0.57cvss 8.7epss 0.01

    Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-7790HigJul 18, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. This affects an unknown part of the file /menu_nat.asp of the component HTTP Request Handler. The manipulation of the argument out_addr/in_addr/out_port/proto leads to stack-based buffer…

  • CVE-2025-54079HigJul 18, 2025
    risk 0.57cvss 8.8epss 0.00

    WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.6 in the endpoint `/html/atendido/Profile_Atendido.php`, in the `idatendido` parameter. This…

  • CVE-2025-54075HigJul 18, 2025
    risk 0.47cvss 8.3epss 0.00

    MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.17.2, a remote script-inclusion / stored cross-site scripting vulnerability in @nuxtjs/mdc lets a Markdown author inject a ``…

  • CVE-2025-54073HigJul 18, 2025
    risk 0.43cvss 7.5epss 0.10

    mcp-package-docs is an MCP (Model Context Protocol) server that provides LLMs with efficient access to package documentation across multiple programming languages and language server protocol (LSP) capabilities. A command injection vulnerability exists in the `mcp-package-docs`…

  • CVE-2025-53945HigJul 18, 2025
    risk 0.39cvss 7.0epss 0.00

    apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. Version 0.29.5 contains a fix for the…

  • CVE-2025-49486HigJul 18, 2025
    risk 0.56cvss epss 0.00

    A stored XSS vulnerability in the Balbooa Gallery plugin 1.0.0-2.4.0 for Joomla allows privileged users to store malicious scripts in gallery items.

  • CVE-2025-49485HigJul 18, 2025
    risk 0.56cvss epss 0.00

    A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' parameter.

  • CVE-2025-49484HigJul 18, 2025
    risk 0.60cvss epss 0.03

    A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL commands via the 'cvid' parameter in the employee application feature.

  • CVE-2025-6023HigJul 18, 2025
    risk 0.46cvss 7.6epss 0.42

    An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions…

  • CVE-2025-38349HigJul 18, 2025
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: eventpoll: don't decrement ep refcount while still holding the ep mutex Jann Horn points out that epoll is decrementing the ep refcount and then doing a mutex_unlock(&ep->mtx); afterwards. That's very…

  • CVE-2025-7438HigJul 18, 2025
    risk 0.49cvss 7.5epss 0.01

    The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'install_and_activate_plugin' function in all versions up to, and including, 4.7.9. This makes it possible for authenticated attackers, with…

  • CVE-2025-6718HigJul 18, 2025
    risk 0.57cvss 8.8epss 0.00

    The B1.lt plugin for WordPress is vulnerable to SQL Injection due to a missing capability check on the b1_run_query AJAX action in all versions up to, and including, 2.2.57. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute…

  • CVE-2025-6813HigJul 18, 2025
    risk 0.57cvss 8.8epss 0.00

    The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within the auto_login() function in versions 1.0 to 1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass…

  • CVE-2025-3740HigJul 18, 2025
    risk 0.57cvss 8.8epss 0.01

    The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 93.1.0 via the 'page' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and…

  • CVE-2025-7765HigJul 17, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/addmanagerclinic.php. The manipulation of the argument clinic leads to sql injection. The attack…

  • CVE-2025-7764HigJul 17, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /admin/deletedoctorclinic.php. The manipulation of the argument clinic leads to sql injection. It is possible to launch the…

  • CVE-2025-7762HigJul 17, 2025
    risk 0.57cvss 8.8epss 0.04

    A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07.26A1. This issue affects some unknown processing of the file /menu_nat_more.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow. The attack may…

  • CVE-2025-7758HigJul 17, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, has been found in TOTOLINK T6 up to 4.1.5cu.748_B20211015. Affected by this issue is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ip…

  • CVE-2025-7397HigJul 17, 2025
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the ascgshell, of Brocade ASCG before 3.3.0 stores any command executed in the Command Line Interface (CLI) in plain text within the command history. A local authenticated user that can access sensitive information like passwords within the CLI history…

  • CVE-2025-7757HigJul 17, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit-property.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely.…