VYPR

CVEs

116,717 total · page 680 of 2,335

  • CVE-2025-6116HigJun 16, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been classified as critical. This affects an unknown part of the file /IntraFieldVehicle/Search of the component API. The manipulation of the argument Value leads to sql injection. It…

  • CVE-2025-6115HigJun 16, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this issue is the function form_macfilter. The manipulation of the argument mac_hostname_%d/sched_name_%d leads to stack-based buffer overflow. The attack may be launched remotely. The…

  • CVE-2025-6114HigJun 16, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this vulnerability is the function form_portforwarding of the file /goform/form_portforwarding. The manipulation of the argument ingress_name_%d/sched_name_%d/name_%d leads to…

  • CVE-2025-40728HigJun 16, 2025
    risk 0.57cvss 8.8epss 0.00

    SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retrieve, create, update and delete databases via the id parameter in the /customer_support/manage_user.php endpoint.

  • CVE-2025-3464HigJun 16, 2025
    risk 0.55cvss epss 0.01

    A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication bypass. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

  • CVE-2025-6113HigJun 16, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. Affected is the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument lanMask leads to buffer overflow. It is possible to launch the attack remotely. The…

  • CVE-2025-6112HigJun 16, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, has been found in Tenda FH1205 2.0.0.7. This issue affects the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument lanMask leads to buffer overflow. The attack may be initiated remotely.…

  • CVE-2025-4987HigJun 16, 2025
    risk 0.57cvss 8.7epss 0.00

    A stored Cross-site Scripting (XSS) vulnerability affecting Opportunity Management in Project Portfolio Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

  • CVE-2025-6111HigJun 16, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical was found in Tenda FH1205 2.0.0.7(775). This vulnerability affects the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be initiated remotely.…

  • CVE-2025-6110HigJun 16, 2025
    risk 0.57cvss 8.8epss 0.04

    A vulnerability classified as critical has been found in Tenda FH1201 1.2.0.14(408). This affects an unknown part of the file /goform/SafeMacFilter. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The…

  • CVE-2025-6104HigJun 16, 2025
    risk 0.57cvss 8.8epss 0.03

    A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects an unknown part of the file /billing/pms_check.php. The manipulation of the argument ipaddress leads to os command injection. It is possible to initiate the…

  • CVE-2025-6103HigJun 16, 2025
    risk 0.57cvss 8.8epss 0.03

    A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affected by this issue is some unknown functionality of the file /billing/test_accesscodelogin.php. The manipulation of the argument Password leads to os command…

  • CVE-2025-6102HigJun 16, 2025
    risk 0.57cvss 8.8epss 0.03

    A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnerability is an unknown functionality of the file /authentication/logout.php. The manipulation of the argument mac_address leads to os command injection. The…

  • CVE-2025-6095HigJun 15, 2025
    risk 0.51cvss 7.3epss 0.02

    A vulnerability, which was classified as critical, was found in codesiddhant Jasmin Ransomware 1.0.1. Affected is an unknown function of the file /checklogin.php. The manipulation of the argument username/password leads to sql injection. It is possible to launch the attack…

  • CVE-2025-5990HigJun 15, 2025
    risk 0.49cvss 7.6epss 0.00

    An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form input.

  • CVE-2025-6091HigJun 15, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function UpdateWanParamsMulti/UpdateIpv6Params of the file /routing/goform/aspForm. The manipulation of the argument param leads to buffer overflow. It is possible to…

  • CVE-2025-6090HigJun 15, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in H3C GR-5400AX V100R009L50 and classified as critical. This issue affects the function UpdateWanparamsMulti/UpdateIpv6params of the file /routing/goform/aspForm. The manipulation of the argument param leads to buffer overflow. The attack may be…

  • CVE-2025-1411HigJun 15, 2025
    risk 0.51cvss 7.8epss 0.00

    IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root due to execution with unnecessary privileges.

  • CVE-2025-4200HigJun 14, 2025
    risk 0.53cvss 8.1epss 0.01

    The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.1 via the load_view() function that is called via at least three AJAX actions: 'load_more_post', 'load_shop', and…

  • CVE-2025-5487HigJun 14, 2025
    risk 0.47cvss 7.2epss 0.00

    The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the field_conditions parameter in all versions up to, and including, 5.2.3 due to insufficient escaping on…

  • CVE-2025-3234HigJun 14, 2025
    risk 0.47cvss 7.2epss 0.01

    The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.8.8. This makes it possible for authenticated attackers, with Administrator-level access and above, to…

  • CVE-2025-33108HigJun 14, 2025
    risk 0.55cvss 8.5epss 0.01

    IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to a library unqualified call made by a BRMS program. A malicious actor could cause user-controlled code to run with…

  • CVE-2025-25215HigJun 13, 2025
    risk 0.57cvss 8.8epss 0.02

    An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an arbitrary free. An attacker can forge a fake session to …

  • CVE-2025-24919HigJun 13, 2025
    risk 0.53cvss 8.1epss 0.02

    A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution. An…

  • CVE-2025-25050HigJun 13, 2025
    risk 0.57cvss 8.8epss 0.02

    An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault 3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an out-of-bounds write. An attacker can…

  • CVE-2025-24922HigJun 13, 2025
    risk 0.57cvss 8.8epss 0.03

    A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted malicious cv_object can lead to a arbitrary code execution. An attacker…

  • CVE-2025-24311HigJun 13, 2025
    risk 0.55cvss 8.4epss 0.02

    An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an information leak. An attacker can issue an API…

  • CVE-2025-49587HigJun 13, 2025
    risk 0.45cvss 8.0epss 0.00

    XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifications.Code.NotificationDisplayerClass object, and later an admin edits and saves that document, the possibly malicious content of that object is output as…

  • CVE-2025-49586HigJun 13, 2025
    risk 0.50cvss 8.8epss 0.01

    XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all users XWiki) can obtain programming right/perform remote code execution by editing the application. This vulnerability has been…

  • CVE-2025-49585HigJun 13, 2025
    risk 0.45cvss 8.0epss 0.00

    XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10.1, when an attacker without script or programming right creates an XClass definition in XWiki (requires edit right), and that same document is later edited by…

  • CVE-2025-49584HigJun 13, 2025
    risk 0.42cvss 7.5epss 0.00

    XWiki is a generic wiki platform. In XWiki Platform versions 10.9 through 16.4.6, 16.5.0-rc-1 through 16.10.2, and 17.0.0-rc-1, the title of every single page whose reference is known can be accessed through the REST API as long as an XClass with a page property is accessible,…

  • CVE-2025-49582HigJun 13, 2025
    risk 0.45cvss 8.0epss 0.01

    XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros that were authored by a user with fewer rights, XWiki warns about the execution of these macros since XWiki 15.9RC1. These required rights analyzers that trigger…

  • CVE-2025-49581HigJun 13, 2025
    risk 0.50cvss 8.8epss 0.01

    XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Groovy, Python, Velocity) with programming right by defining a wiki macro. This allows full access to the whole XWiki installation. The main problem is that if a…

  • CVE-2025-49580HigJun 13, 2025
    risk 0.45cvss 8.0epss 0.00

    XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or programming rights when they contain a link and the target of the link is renamed or moved. This might lead to execution of scripts contained in xobjects that…

  • CVE-2025-48920HigJun 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal etracker allows Cross-Site Scripting (XSS).This issue affects etracker: from 0.0.0 before 3.1.0.

  • CVE-2025-48918HigJun 13, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0.

  • CVE-2025-48915HigJun 13, 2025
    risk 0.56cvss 8.6epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.15.

  • CVE-2025-48914HigJun 13, 2025
    risk 0.56cvss 8.6epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.15.

  • CVE-2025-36633HigJun 13, 2025
    risk 0.57cvss 8.8epss 0.00

    In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation.

  • CVE-2025-36631HigJun 13, 2025
    risk 0.55cvss 8.4epss 0.00

    In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.

  • CVE-2025-28382HigJun 13, 2025
    risk 0.42cvss 7.5epss 0.01

    An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

  • CVE-2025-28381HigJun 13, 2025
    risk 0.00cvss 7.5epss 0.00

    A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.

  • CVE-2025-49468HigJun 13, 2025
    risk 0.56cvss epss 0.00

    A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. The vulnerability allows remote authenticated users to execute arbitrary SQL commands via the id_module parameter.

  • CVE-2025-39240HigJun 13, 2025
    risk 0.47cvss 7.2epss 0.01

    Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to…

  • CVE-2025-22239HigJun 13, 2025
    risk 0.46cvss 8.1epss 0.00

    Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event bus.

  • CVE-2025-22236HigJun 13, 2025
    risk 0.53cvss 8.1epss 0.00

    Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).

  • CVE-2025-5282HigJun 13, 2025
    risk 0.42cvss 7.5epss 0.00

    The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_package() function in all versions up to, and including, 6.5.1. This makes it possible for…

  • CVE-2025-5491HigJun 13, 2025
    risk 0.57cvss 8.8epss 0.01

    Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing remote users with low privileges to interact with it and access…

  • CVE-2025-47959HigJun 13, 2025
    risk 0.47cvss 7.1epss 0.07

    Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.

  • CVE-2025-30399HigJun 13, 2025
    risk 0.49cvss 7.5epss 0.01

    Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.