VYPR

CVEs

116,641 total · page 689 of 2,333

  • CVE-2025-5583HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /register.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed…

  • CVE-2018-25112HigJun 4, 2025
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated remote attacker may use an uncontrolled resource consumption in the IEC 61131 program of the affected products by creating large amounts of network traffic that needs to be handled by the ILC. This results in a Denial-of-Service of the device.

  • CVE-2025-5581HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument User leads to sql injection. The attack can be initiated remotely.…

  • CVE-2025-5580HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been classified as critical. This affects an unknown part of the file /login.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The…

  • CVE-2025-5579HigJun 4, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Dairy Farm Shop Management System 1.3 and classified as critical. Affected by this issue is some unknown functionality of the file /search-product.php. The manipulation of the argument productname leads to sql injection. The attack may be…

  • CVE-2025-5578HigJun 4, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in PHPGurukul Dairy Farm Shop Management System 1.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /sales-report-details.php. The manipulation of the argument fromdate/todate leads to sql…

  • CVE-2025-5577HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in PHPGurukul Dairy Farm Shop Management System 1.3. Affected is an unknown function of the file /profile.php. The manipulation of the argument mobilenumber leads to sql injection. It is possible to launch the attack…

  • CVE-2025-5576HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in PHPGurukul Dairy Farm Shop Management System 1.3. This issue affects some unknown processing of the file /bwdate-report-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The…

  • CVE-2025-5482HigJun 4, 2025
    risk 0.57cvss 8.8epss 0.01

    The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.11. This is due to the plugin not properly validating a user-supplied key. This makes…

  • CVE-2025-47728HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2025-47727HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2025-47726HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2025-47725HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2025-47724HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2024-13967HigJun 4, 2025
    risk 0.57cvss 8.8epss 0.00

    This vulnerability allows the successful attacker to gain unauthorized access to a configuration web page delivered by the integrated web Server of EIBPORT. This issue affects EIBPORT V3 KNX: through 3.9.8; EIBPORT V3 KNX GSM: through 3.9.8.

  • CVE-2025-5575HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in PHPGurukul Dairy Farm Shop Management System 1.3. This vulnerability affects unknown code of the file /add-product.php. The manipulation of the argument productname leads to sql injection. The attack can be initiated remotely.…

  • CVE-2025-5574HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in PHPGurukul Dairy Farm Shop Management System 1.3. This affects an unknown part of the file /add-company.php. The manipulation of the argument companyname leads to sql injection. It is possible to initiate the attack…

  • CVE-2025-5572HigJun 4, 2025
    risk 0.58cvss 8.8epss 0.05

    A vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. Affected by this vulnerability is the function setSystemEmail of the file /setSystemEmail. The manipulation of the argument EmailSMTPPortNumber leads to stack-based buffer overflow. The…

  • CVE-2025-5562HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/edit-category-detail.php. The manipulation of the argument editid leads to sql injection. The…

  • CVE-2025-5561HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/view-pass-detail.php. The manipulation of the argument viewid leads to sql injection. The…

  • CVE-2024-31127HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker to elevate their privileges.

  • CVE-2025-5560HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /index.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack…

  • CVE-2025-5553HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /download-pass.php. The manipulation of the argument searchdata leads to sql injection. The attack can be…

  • CVE-2025-5551HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. This affects an unknown part of the component SYSTEM Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2025-5550HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this issue is some unknown functionality of the component PBSZ Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been…

  • CVE-2025-5549HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component PASV Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit…

  • CVE-2025-5548HigJun 4, 2025
    risk 0.51cvss 7.3epss 0.13

    A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component NOOP Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2025-5547HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. This issue affects some unknown processing of the component CDUP Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-5527HigJun 3, 2025
    risk 0.58cvss 8.8epss 0.10

    A vulnerability was found in Tenda RX3 16.03.13.11_multi_TDE01. It has been rated as critical. This issue affects the function save_staticroute_data of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack may…

  • CVE-2025-48999HigJun 3, 2025
    risk 0.00cvss 8.8epss 0.08

    DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10. In a malicious payload, `getUrlType()` retrieves `hostName`. Since the judgment statement returns false, it will not enter the if…

  • CVE-2025-35036HigJun 3, 2025
    risk 0.41cvss 7.3epss 0.01

    Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code.…

  • CVE-2025-23100HigJun 3, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. The absence of a NULL check leads to a Denial of Service.

  • CVE-2025-23098HigJun 3, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380. A Use-After-Free in the mobile processor leads to privilege escalation.

  • CVE-2025-5522HigJun 3, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sa/addUser of the component User Creation Handler. The…

  • CVE-2025-48998HigJun 3, 2025
    risk 0.57cvss 8.8epss 0.00

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the patch for CVE-2025-27103 allows authenticated users to read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been…

  • CVE-2025-48997HigJun 3, 2025
    risk 0.50cvss epss 0.00

    Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.1 allows an attacker to trigger a Denial of Service (DoS) by sending an upload file request with an empty string field…

  • CVE-2025-48950HigJun 3, 2025
    risk 0.00cvss 8.8epss 0.00

    MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution permissions of binary files in common directories, such as `/bin,/usr/bin`, etc. Therefore, attackers can exploit some files with execution permissions in non…

  • CVE-2025-23102HigJun 3, 2025
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380, 1480 and 2400. A Double Free in the mobile processor leads to privilege escalation.

  • CVE-2025-5512HigJun 3, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file /api/sys/user/verifyPassword/ of the component Administrator Backend. The manipulation leads to improper authentication. It is possible…

  • CVE-2025-30167HigJun 3, 2025
    risk 0.40cvss 7.3epss 0.00

    Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the shared `%PROGRAMDATA%` directory is searched for configuration files (`SYSTEM_CONFIG_PATH` and `SYSTEM_JUPYTER_PATH`), which may allow…

  • CVE-2025-23107HigJun 3, 2025
    risk 0.56cvss 8.6epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.

  • CVE-2025-25021HigJun 3, 2025
    risk 0.47cvss 7.2epss 0.01

    IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code in case management script creation due to the improper generation of code.

  • CVE-2025-23103HigJun 3, 2025
    risk 0.56cvss 8.6epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.

  • CVE-2025-5503HigJun 3, 2025
    risk 0.57cvss 8.8epss 0.05

    A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. This affects the function formMapReboot of the file /boafrm/formMapReboot. The manipulation of the argument deviceMacAddr leads to stack-based buffer overflow. It is possible to…

  • CVE-2025-36564HigJun 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation.

  • CVE-2025-5499HigJun 3, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function is_file/getimagesize of the file image_resized.php. The manipulation of the argument imgfile leads to deserialization. It is possible to launch the attack…

  • CVE-2025-46154HigJun 3, 2025
    risk 0.55cvss 8.4epss 0.00

    Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.

  • CVE-2025-5495HigJun 3, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Netgear WNR614 1.1.0.28_1.0.1WW. It has been classified as critical. This affects an unknown part of the component URL Handler. The manipulation with the input %00currentsetting.htm leads to improper authentication. It is possible to initiate the…

  • CVE-2025-4435HigJun 3, 2025
    risk 0.42cvss 7.5epss 0.01

    When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and…

  • CVE-2025-4330HigJun 3, 2025
    risk 0.42cvss 7.5epss 0.01

    Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using…