VYPR

CVEs

116,729 total · page 671 of 2,335

  • CVE-2025-23264HigJun 24, 2025
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code injection issue by providing a malicious file. A successful exploit of this vulnerability may lead to Code Execution, Escalation of Privileges, Information…

  • CVE-2025-6568HigJun 24, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formIpv6Setup of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow.…

  • CVE-2025-6567HigJun 24, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file Recruitment/admin/view_application.php. The manipulation of the argument ID leads to sql injection. The attack…

  • CVE-2025-36537HigJun 24, 2025
    risk 0.46cvss 7.0epss 0.00

    Incorrect Permission Assignment for Critical Resource in the TeamViewer Client (Full and Host) of TeamViewer Remote and Tensor prior Version 15.67 on Windows allows a local unprivileged user to trigger arbitrary file deletion with SYSTEM privileges via leveraging the MSI…

  • CVE-2025-32978HigJun 24, 2025
    risk 0.49cvss 7.5epss 0.01

    Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unauthenticated users to replace system licenses through a web interface intended…

  • CVE-2025-32976HigJun 24, 2025
    risk 0.57cvss 8.8epss 0.01

    Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains a logic flaw in its two-factor authentication implementation that allows…

  • CVE-2025-6032HigJun 24, 2025
    risk 0.47cvss 8.3epss 0.00

    A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

  • CVE-2025-27828HigJun 24, 2025
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4, 10.1.0.0 through 10.1.0.5, and 10.2.0.0 through 10.2.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input…

  • CVE-2025-27827HigJun 24, 2025
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.2.0.3 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper handling of session data. A successful exploit requires user interaction and could…

  • CVE-2025-6565HigJun 24, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Netgear WNCE3001 1.0.0.50. It has been classified as critical. This affects the function http_d of the component HTTP POST Request Handler. The manipulation of the argument Host leads to stack-based buffer overflow. It is possible to initiate the…

  • CVE-2025-6436HigJun 24, 2025
    risk 0.53cvss 8.1epss 0.03

    Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 140 and…

  • CVE-2025-6435HigJun 24, 2025
    risk 0.53cvss 8.1epss 0.00

    If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability was fixed in…

  • CVE-2025-6432HigJun 24, 2025
    risk 0.56cvss 8.6epss 0.00

    When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

  • CVE-2025-6426HigJun 24, 2025
    risk 0.57cvss 8.8epss 0.00

    The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and…

  • CVE-2025-39202HigJun 24, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and overwrite files causing information leak and data corruption.

  • CVE-2025-2403HigJun 24, 2025
    risk 0.49cvss 7.5epss 0.00

    A denial-of-service vulnerability due to improper prioritization of network traffic over protection mechanism exists in Relion 670/650 and SAM600-IO series device that if exploited could potentially cause critical functions like LDCM (Line Distance Communication Module) to…

  • CVE-2025-6206HigJun 24, 2025
    risk 0.49cvss 7.5epss 0.00

    The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aiomatic_image_editor_ajax_submit' function in all versions up to, and…

  • CVE-2025-3092HigJun 24, 2025
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint.

  • CVE-2025-3091HigJun 24, 2025
    risk 0.49cvss 7.5epss 0.00

    An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s password.

  • CVE-2025-3090HigJun 24, 2025
    risk 0.53cvss 8.2epss 0.00

    An unauthenticated remote attacker can obtain limited sensitive information and/or DoS the device due to missing authentication for critical function.

  • CVE-2025-2962HigJun 24, 2025
    risk 0.49cvss 7.5epss 0.00

    A denial-of-service issue in the dns implemenation could cause an infinite loop.

  • CVE-2025-41427HigJun 24, 2025
    risk 0.57cvss 8.8epss 0.01

    WRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Connection Diagnostics page. If a remote authenticated attacker sends a specially crafted request to the affected…

  • CVE-2025-52568HigJun 24, 2025
    risk 0.50cvss epss 0.00

    NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issues that can lead to memory corruption, disk image corruption, denial of service, and potential code execution. These issues stem from unchecked memory…

  • CVE-2025-52566HigJun 24, 2025
    risk 0.00cvss 8.6epss 0.00

    llama.cpp is an inference of several LLM models in C/C++. Prior to version b5721, there is a signed vs. unsigned integer overflow in llama.cpp's tokenizer implementation (llama_vocab::tokenize) (src/llama-vocab.cpp:3036) resulting in unintended behavior in tokens copying size…

  • CVE-2025-52574HigJun 24, 2025
    risk 0.42cvss 7.5epss 0.00

    SysmonElixir is a system monitor HTTP service in Elixir. Prior to version 1.0.1, the /read endpoint reads any file from the server's /etc/passwd by default. In v1.0.1, a whitelist was added that limits reading to only files under priv/data. This issue has been patched in version…

  • CVE-2025-52560HigJun 24, 2025
    risk 0.00cvss 8.1epss 0.00

    Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard allows password reset emails to be sent with URLs derived from the unvalidated Host header when the application_url configuration is unset (default behavior). This…

  • CVE-2025-48466HigJun 24, 2025
    risk 0.53cvss 8.1epss 0.01

    Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs, potentially allowing remote control of relay channel which may lead to operational or safety risks.

  • CVE-2025-34038HigJun 24, 2025
    risk 0.49cvss 7.5epss 0.02

    A SQL injection vulnerability exists in Weaver E-cology 8.0 via the getdata.jsp endpoint. The application directly passes unsanitized user input from the sql parameter into a database query within the getSelectAllIds(sql, type) method, reachable through the cmd=getSelectAllId…

  • CVE-2025-34034HigJun 24, 2025
    risk 0.57cvss 8.8epss 0.01

    A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts allow unauthenticated or…

  • CVE-2025-34033HigJun 24, 2025
    risk 0.58cvss 8.8epss 0.04

    An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ping_addr parameter in the webctrl.cgi script. The application fails to properly sanitize input before passing it to the system-level ping command. An…

  • CVE-2025-34031HigJun 24, 2025
    risk 0.49cvss 7.5epss 0.03

    A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsmol.php. The script directly passes user input to the file_get_contents() function without proper validation, allowing attackers to read arbitrary files from…

  • CVE-2025-6529HigJun 23, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in 70mai M300 up to 20250611 and classified as critical. Affected by this issue is some unknown functionality of the component Telnet Service. The manipulation leads to use of default credentials. The attack needs to be initiated within the local…

  • CVE-2025-52558HigJun 23, 2025
    risk 0.39cvss epss 0.01

    changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Prior to version 0.50.4, errors in filters from website page change detection watches were not being filtered resulting in a cross-site scripting (XSS)…

  • CVE-2025-23092HigJun 23, 2025
    risk 0.47cvss 7.2epss 0.01

    Mitel OpenScape Accounting Management through V5 R1.1.0 could allow an authenticated attacker with administrative privileges to conduct a path traversal attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to upload arbitrary files…

  • CVE-2025-48026HigJun 23, 2025
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7R1 FR5 HF43 P913 could allow an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. A successful exploit could allow an attacker to read files from the…

  • CVE-2025-44528HigJun 23, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in Texas Instruments LP-CC2652RB SimpleLink CC13XX CC26XX SDK 7.41.00.17 allows attackers to cause a Denial of Service (DoS) via sending a crafted LL_Pause_Enc_Req packet during the authentication and connection phase, causing a Denial of Service (DoS).

  • CVE-2025-50349HigJun 23, 2025
    risk 0.49cvss 7.5epss 0.01

    PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-teacher-pic.php.

  • CVE-2025-50348HigJun 23, 2025
    risk 0.49cvss 7.5epss 0.01

    PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-class-pic.php.

  • CVE-2025-49144HigJun 23, 2025
    risk 0.40cvss 7.3epss 0.01

    Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker…

  • CVE-2025-49126HigJun 23, 2025
    risk 0.50cvss 8.8epss 0.00

    Visionatrix is an AI Media processing tool using ComfyUI. In versions 1.5.0 to before 2.5.1, the /docs/flows endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack allowing full takeover of the application and exfiltration of secrets stored in the application.…

  • CVE-2025-6511HigJun 23, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical has been found in Netgear EX6150 1.0.0.46_1.0.76. This affects the function sub_410090. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…

  • CVE-2025-6510HigJun 23, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Netgear EX6100 1.0.2.28_1.1.138. It has been rated as critical. Affected by this issue is the function sub_415EF8. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the…

  • CVE-2023-50450HigJun 23, 2025
    risk 0.55cvss 8.4epss 0.00

    An issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified actions with elevated privileges.

  • CVE-2023-47294HigJun 23, 2025
    risk 0.53cvss 8.1epss 0.00

    An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, lock, and delete user accounts via a crafted session cookie.

  • CVE-2025-2171HigJun 23, 2025
    risk 0.51cvss epss 0.00

    Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN

  • CVE-2025-52922HigJun 23, 2025
    risk 0.48cvss 7.4epss 0.00

    Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully map the filesystem structure via the /api/file_manager/files?base_folder= endpoint, (2) create arbitrary…

  • CVE-2025-23049HigJun 23, 2025
    risk 0.55cvss epss 0.02

    Meridian Technique Materialise OrthoView through 7.5.1 allows OS Command Injection when servlet sharing is enabled.

  • CVE-2025-27387HigJun 23, 2025
    risk 0.48cvss 7.4epss 0.00

    OPPO Clone Phone uses a weak password WiFi hotspot to transfer files, resulting in Information disclosure.

  • CVE-2025-6503HigJun 23, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php_action/fetchSelectedCategories.php. The manipulation of the argument categoriesId leads to sql injection. The attack…

  • CVE-2025-6502HigJun 23, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php_action/changePassword.php. The manipulation of the argument user_id leads to sql injection. The attack can be…