VYPR

CVEs

116,636 total · page 690 of 2,333

  • CVE-2024-36486HigJun 3, 2025
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Desktop for Mac version 20.1.1 (55740). When an archived virtual machine is restored, the prl_vmarchiver tool decompresses the file and writes the content back to…

  • CVE-2025-46355HigJun 3, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SYSTEM privilege on Windows system where the product is running by a local authenticated attacker.

  • CVE-2025-21479HigKEVJun 3, 2025
    risk 0.68cvss 8.6epss 0.01

    Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

  • CVE-2025-27038HigKEVJun 3, 2025
    risk 0.61cvss 7.5epss 0.01

    Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

  • CVE-2025-27031HigJun 3, 2025
    risk 0.51cvss 7.8epss 0.00

    memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed.

  • CVE-2025-27029HigJun 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.

  • CVE-2025-21486HigJun 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption during dynamic process creation call when client is only passing address and length of shell binary.

  • CVE-2025-21485HigJun 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC.

  • CVE-2025-21480HigKEVJun 3, 2025
    risk 0.68cvss 8.6epss 0.00

    Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

  • CVE-2025-21463HigJun 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing the EHT operation IE in the received beacon frame.

  • CVE-2024-53026HigJun 3, 2025
    risk 0.53cvss 8.2epss 0.00

    Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.

  • CVE-2024-53021HigJun 3, 2025
    risk 0.53cvss 8.2epss 0.00

    Information disclosure may occur while processing goodbye RTCP packet from network.

  • CVE-2024-53020HigJun 3, 2025
    risk 0.53cvss 8.2epss 0.00

    Information disclosure may occur while decoding the RTP packet with invalid header extension from network.

  • CVE-2024-53019HigJun 3, 2025
    risk 0.53cvss 8.2epss 0.00

    Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources.

  • CVE-2024-53010HigJun 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption may occur while attaching VM when the HLOS retains access to VM.

  • CVE-2025-4224HigJun 3, 2025
    risk 0.47cvss 7.2epss 0.00

    The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload names in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2025-5419HigKEVJun 3, 2025
    risk 0.70cvss 8.8epss 0.08

    Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-5068HigJun 3, 2025
    risk 0.57cvss 8.8epss 0.03

    Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2025-48387HigJun 2, 2025
    risk 0.50cvss epss 0.01

    tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9, 2.1.3, and 1.16.5. As a workaround, use the ignore…

  • CVE-2025-23105HigJun 2, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.

  • CVE-2025-1051HigJun 2, 2025
    risk 0.57cvss 8.8epss 0.00

    Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. The specific flaw…

  • CVE-2025-27956HigJun 2, 2025
    risk 0.49cvss 7.5epss 0.01

    Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via the id parameter.

  • CVE-2025-20298HigJun 2, 2025
    risk 0.52cvss 8.0epss 0.00

    In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\Program…

  • CVE-2025-5036HigJun 2, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

  • CVE-2025-48940HigJun 2, 2025
    risk 0.00cvss 7.2epss 0.01

    MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input properly, which allows attackers to perform local file inclusion (LFI) via a specially crafted parameter value. In order to exploit the vulnerability, the…

  • CVE-2025-48866HigJun 2, 2025
    risk 0.00cvss 7.5epss 0.01

    ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `sanitizeArg` - this is the…

  • CVE-2025-45542HigJun 2, 2025
    risk 0.51cvss 7.3epss 0.01

    SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is vulnerable due to improper input validation, allowing attackers to inject SQL queries.

  • CVE-2024-57459HigJun 2, 2025
    risk 0.47cvss 7.3epss 0.00

    A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds parameter does not properly validate user input, allowing an attacker to inject arbitrary SQL commands.

  • CVE-2024-54028HigJun 2, 2025
    risk 0.55cvss 8.4epss 0.00

    An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2024-52035HigJun 2, 2025
    risk 0.55cvss 8.4epss 0.00

    An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2024-48877HigJun 2, 2025
    risk 0.55cvss 8.4epss 0.00

    A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility version 0.95. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2025-37091HigJun 2, 2025
    risk 0.47cvss 7.2epss 0.01

    A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

  • CVE-2024-57783HigJun 2, 2025
    risk 0.53cvss 8.1epss 0.00

    The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.

  • CVE-2025-26396HigJun 2, 2025
    risk 0.51cvss 7.8epss 0.00

    The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vulnerability requires local access and a valid low privilege account to be susceptible to this vulnerability.

  • CVE-2024-12168HigJun 2, 2025
    risk 0.51cvss 7.8epss 0.00

    Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used.

  • CVE-2025-48990HigJun 2, 2025
    risk 0.49cvss epss 0.00

    NeKernal is a free and open-source operating system stack. Version 0.0.2 has a 1-byte heap overflow in `rt_copy_memory`, which unconditionally wrote a null terminator at `dst[len]`. When `len` equals the size of the destination buffer (256 bytes), that extra `'\0'` write…

  • CVE-2025-48957HigJun 2, 2025
    risk 0.42cvss 7.5epss 0.01

    AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions 3.4.4 through 3.5.12 may lead to information disclosure, such as API keys for LLM providers, account passwords, and other sensitive data. The vulnerability has…

  • CVE-2025-46807HigJun 2, 2025
    risk 0.50cvss epss 0.00

    A Allocation of Resources Without Limits or Throttling vulnerability in sslh allows attackers to easily exhaust the file descriptors in sslh and deny legitimate users service.This issue affects sslh before 2.2.4.

  • CVE-2025-29785HigJun 2, 2025
    risk 0.42cvss 7.5epss 0.00

    quic-go is an implementation of the QUIC protocol in Go. The loss recovery logic for path probe packets that was added in the v0.50.0 release can be used to trigger a nil-pointer dereference by a malicious QUIC client. In order to do so, the attacker first sends valid QUIC…

  • CVE-2025-1246HigJun 2, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU…

  • CVE-2025-0819HigJun 2, 2025
    risk 0.51cvss 7.8epss 0.00

    Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to gain access to already freed…

  • CVE-2025-0073HigJun 2, 2025
    risk 0.51cvss 7.8epss 0.00

    Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gain access to already freed memory.This issue affects Valhall…

  • CVE-2025-3260HigJun 2, 2025
    risk 0.47cvss 8.3epss 0.01

    A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all dashboards/folders…

  • CVE-2025-5455HigJun 2, 2025
    risk 0.55cvss epss 0.00

    An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a…

  • CVE-2025-5435HigJun 2, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Marwal Infotech CMS 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /page.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…

  • CVE-2025-5113HigJun 2, 2025
    risk 0.56cvss epss 0.08

    The Diviotec professional series exposes a web interface. One endpoint is vulnerable to arbitrary command injection and hardcoded passwords are used.

  • CVE-2025-0358HigJun 2, 2025
    risk 0.57cvss 8.8epss 0.00

    During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.

  • CVE-2025-5434HigJun 2, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Aem Solutions CMS up to 1.0. It has been classified as critical. This affects an unknown part of the file /page.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2025-4010HigJun 2, 2025
    risk 0.56cvss epss 0.01

    The Netcom NTC 6200 and NWL 222 series expose a web interface to be configured and set up by operators. Multiple endpoints of the web interface are vulnerable to arbitrary command injection and use insecure hardcoded passwords. Remote authenticated attackers can gain arbitrary…

  • CVE-2025-25179HigJun 2, 2025
    risk 0.51cvss 7.8epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages.