VYPR

CVEs

116,914 total · page 654 of 2,339

  • CVE-2025-34106HigJul 15, 2025
    risk 0.58cvss epss 0.00

    A buffer overflow vulnerability exists in PDF Shaper versions 3.5 and 3.6 when converting a crafted PDF file to an image using the 'Convert PDF to Image' functionality. An attacker can exploit this vulnerability by tricking a user into opening a maliciously crafted PDF file,…

  • CVE-2025-7667HigJul 15, 2025
    risk 0.53cvss 8.1epss 0.00

    The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'restrict-file-access' page. This makes it possible for unauthenticated attackers to…

  • CVE-2025-6265HigJul 15, 2025
    risk 0.47cvss 7.2epss 0.01

    A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and earlier could allow an authenticated attacker with administrator privileges to access specific directories and delete files, such as the configuration file,…

  • CVE-2025-53823HigJul 14, 2025
    risk 0.57cvss 8.8epss 0.00

    WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior to 3.4.5 have a SQL Injection vulnerability in the endpoint `/WeGIA/html/socio/sistema/processa_deletar_socio.php`, in the `id_socio` parameter. This…

  • CVE-2025-53819HigJul 14, 2025
    risk 0.44cvss 7.9epss 0.00

    Nix is a package manager for Linux and other Unix systems. Builds with Nix 2.30.0 on macOS were executed with elevated privileges (root), instead of the build users. The fix was applied to Nix 2.30.1. No known workarounds are available.

  • CVE-2025-53818HigJul 14, 2025
    risk 0.58cvss epss 0.01

    GitHub Kanban MCP Server is a Model Context Protocol (MCP) server for managing GitHub issues in Kanban board format and streamlining LLM task management. Version 0.3.0 of the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of…

  • CVE-2025-53643HigJul 14, 2025
    risk 0.42cvss 7.5epss 0.00

    AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request. If a pure Python version of aiohttp is installed…

  • CVE-2025-53623HigJul 14, 2025
    risk 0.46cvss epss 0.01

    The Job Iteration API is an an extension for ActiveJob that make jobs interruptible and resumable Versions prior to 1.11.0 have an arbitrary code execution vulnerability in the `CsvEnumerator` class. This vulnerability can be exploited by an attacker to execute arbitrary…

  • CVE-2025-53101HigJul 14, 2025
    risk 0.41cvss 7.4epss 0.01

    ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in a filename template causes internal…

  • CVE-2025-53015HigJul 14, 2025
    risk 0.42cvss 7.5epss 0.01

    ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion command. Version 7.1.2-0 fixes the issue.

  • CVE-2024-42646HigJul 14, 2025
    risk 0.49cvss 7.5epss 0.00

    A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages.

  • CVE-2025-7612HigJul 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Mobile Shop 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2025-7611HigJul 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Wedding Reservation 1.0. It has been classified as critical. This affects an unknown part of the file /global.php. The manipulation of the argument lu leads to sql injection. It is possible to initiate the attack remotely. The exploit…

  • CVE-2025-7610HigJul 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Electricity Billing System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user/change_password.php. The manipulation of the argument new_password leads to sql injection. The attack may…

  • CVE-2025-7609HigJul 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in code-projects Simple Shopping Cart 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument ruser_email leads to sql injection. The attack can be…

  • CVE-2025-7608HigJul 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability, which was classified as critical, was found in code-projects Simple Shopping Cart 1.0. Affected is an unknown function of the file /userlogin.php. The manipulation of the argument user_email leads to sql injection. It is possible to launch the attack remotely.…

  • CVE-2025-7607HigJul 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability, which was classified as critical, has been found in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Customers/save_order.php. The manipulation of the argument order_price leads to sql injection. The attack may be…

  • CVE-2025-7606HigJul 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical has been found in code-projects AVL Rooms 1.0. This affects an unknown part of the file /city.php. The manipulation of the argument city leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed…

  • CVE-2025-7605HigJul 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects AVL Rooms 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /profile.php. The manipulation of the argument first_name leads to sql injection. The attack may be launched remotely. The…

  • CVE-2025-7604HigJul 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /user-login.php. The manipulation of the argument Username leads to sql injection. The attack can be…

  • CVE-2025-7603HigJul 14, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. Affected is an unknown function of the file /jingx.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack…

  • CVE-2025-27582HigJul 14, 2025
    risk 0.49cvss 7.6epss 0.00

    The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issue arises from a flawed security hardening mechanism within the kiosk browser used to display the Password Self-Service site to end users. Specifically, the…

  • CVE-2025-7602HigJul 14, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was found in D-Link DI-8100 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /arp_sys.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow. The attack may be initiated…

  • CVE-2025-7598HigJul 14, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical was found in Tenda AX1803 1.0.0.1. Affected by this vulnerability is the function formSetWifiMacFilterCfg of the file /goform/setWifiFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack can…

  • CVE-2025-7597HigJul 14, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical has been found in Tenda AX1803 1.0.0.1. Affected is the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. It is possible to launch the attack…

  • CVE-2025-7596HigJul 14, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda FH1205 2.0.0.7(775). It has been rated as critical. This issue affects the function formWifiExtraSet of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. The attack may be…

  • CVE-2025-7595HigJul 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Job Diary 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /view-cad.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2024-51770HigJul 14, 2025
    risk 0.49cvss 7.5epss 0.00

    An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

  • CVE-2024-51769HigJul 14, 2025
    risk 0.49cvss 7.5epss 0.00

    An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

  • CVE-2024-51768HigJul 14, 2025
    risk 0.52cvss 8.0epss 0.00

    An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

  • CVE-2024-51767HigJul 14, 2025
    risk 0.48cvss 7.3epss 0.01

    An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

  • CVE-2025-7594HigJul 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Job Diary 1.0. It has been classified as critical. This affects an unknown part of the file /view-emp.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2025-7593HigJul 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Job Diary 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view-all.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has…

  • CVE-2025-53689HigJul 14, 2025
    risk 0.50cvss 8.8epss 0.00

    Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta…

  • CVE-2024-26293HigJul 14, 2025
    risk 0.57cvss epss 0.00

    The Avid Nexis Agent uses a vulnerable gSOAP version. An undocumented vulnerability impacting gSOAP v2.8 makes the application vulnerable to an Unauthenticated Path Traversal vulnerability. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before…

  • CVE-2025-7587HigJul 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Online Appointment Booking System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /cover.php. The manipulation of the argument uname/psw leads to sql injection. The attack may be…

  • CVE-2024-26292HigJul 14, 2025
    risk 0.46cvss epss 0.00

    An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1.

  • CVE-2024-26291HigJul 14, 2025
    risk 0.57cvss epss 0.01

    An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filename does not validate the path thus allowing users to read arbitrary files. As the application runs with the highest privileges (root/NT_AUTHORITY SYSTEM) by…

  • CVE-2025-7586HigJul 14, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been declared as critical. Affected by this vulnerability is the function formSetAPCfg of the file /goform/setWtpData. The manipulation of the argument radio_2g_1 leads to stack-based buffer overflow. The attack can…

  • CVE-2025-7576HigJul 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16 and classified as critical. Affected by this issue is some unknown functionality of the file /priv/production/production.html of the component Production Tools. The manipulation leads to…

  • CVE-2025-7571HigJul 14, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical has been found in UTT HiPER 840G up to 3.1.1-190328. This affects an unknown part of the file /goform/aspApBasicConfigUrcp. The manipulation of the argument Username leads to buffer overflow. It is possible to initiate the attack remotely.…

  • CVE-2025-7620HigJul 14, 2025
    risk 0.57cvss 8.8epss 0.00

    The cross-browser document creation component produced by Digitware System Integration Corporation has a Remote Code Execution vulnerability. If a user visits a malicious website while the component is active, remote attackers can cause the system to download and execute…

  • CVE-2025-7619HigJul 14, 2025
    risk 0.57cvss 8.8epss 0.01

    BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File Write vulnerability. If a user visits a malicious website while the application is running, remote attackers can write arbitrary files to any path and potentially lead to arbitrary code…

  • CVE-2025-7570HigJul 14, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been rated as critical. Affected by this issue is some unknown functionality of the file /goform/aspRemoteApConfTempSend. The manipulation of the argument remoteSrcTemp leads to buffer overflow. The attack…

  • CVE-2025-7564HigJul 14, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC3600 1.0.22. Affected by this issue is some unknown functionality of the file /etc/shadow. The manipulation with the input root:blinkadmin leads to hard-coded credentials. Local access is required…

  • CVE-2025-25180HigJul 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages…

  • CVE-2025-7551HigJul 14, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda FH1201 1.2.0.14(408). It has been declared as critical. Affected by this vulnerability is the function fromPptpUserAdd of the file /goform/PPTPDClient. The manipulation of the argument modino/username leads to stack-based buffer overflow. The…

  • CVE-2025-1384HigJul 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software. An attacker may use this vulnerability to perform unauthorized access and to execute unauthorized code…

  • CVE-2025-7550HigJul 13, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda FH1201 1.2.0.14(408). It has been classified as critical. Affected is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer. The manipulation of the argument dips leads to stack-based buffer overflow. It is possible to launch the…

  • CVE-2025-7549HigJul 13, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda FH1201 1.2.0.14(408) and classified as critical. This issue affects the function frmL7ProtForm of the file /goform/L7Prot. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The…