VYPR

CVEs

116,624 total · page 696 of 2,333

  • CVE-2024-9639HigMay 22, 2025
    risk 0.52cvss 8.0epss 0.01

    Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

  • CVE-2024-52874HigMay 22, 2025
    risk 0.58cvss 8.8epss 0.10

    In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.

  • CVE-2024-13931HigMay 22, 2025
    risk 0.47cvss 7.2epss 0.00

    Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

  • CVE-2024-13929HigMay 22, 2025
    risk 0.47cvss 7.2epss 0.01

    Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

  • CVE-2024-13928HigMay 22, 2025
    risk 0.47cvss 7.2epss 0.00

    SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

  • CVE-2025-47780HigMay 22, 2025
    risk 0.51cvss 7.8epss 0.00

    Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be run via the Asterisk command line interface (CLI)…

  • CVE-2025-47779HigMay 22, 2025
    risk 0.50cvss 7.7epss 0.01

    Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, SIP requests of the type MESSAGE (RFC 3428) authentication do not get proper alignment. An…

  • CVE-2025-46715HigMay 22, 2025
    risk 0.51cvss 7.8epss 0.00

    Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to version 1.15.12, Api_GetSecureParam fails to sanitize incoming pointers, and implicitly trusts that the pointer the user has passed in…

  • CVE-2025-45472HigMay 22, 2025
    risk 0.57cvss 8.8epss 0.00

    Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer cloud account.

  • CVE-2025-43596HigMay 22, 2025
    risk 0.51cvss 7.8epss 0.00

    An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially crafted file with an arbitrary file backup target. Upgrade to MSP360 Backup 8.1.1.19 (released on 2025-05-15).

  • CVE-2025-33137HigMay 22, 2025
    risk 0.46cvss 7.1epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.

  • CVE-2025-33136HigMay 22, 2025
    risk 0.46cvss 7.1epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.

  • CVE-2024-48850HigMay 22, 2025
    risk 0.47cvss 7.2epss 0.00

    Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

  • CVE-2025-5081HigMay 22, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in Campcodes Cybercafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adminprofile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be…

  • CVE-2025-45468HigMay 22, 2025
    risk 0.57cvss 8.8epss 0.00

    Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the customer cloud account.

  • CVE-2025-5080HigMay 22, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function webExcptypemanFilter of the file /goform/webExcptypemanFilter. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack…

  • CVE-2025-5079HigMay 22, 2025
    risk 0.47cvss 7.3epss 0.01

    A flaw has been found in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/updateorder.php. Executing manipulation of the argument remark can lead to sql injection. The attack may be performed from…

  • CVE-2025-5024HigMay 22, 2025
    risk 0.48cvss 7.4epss 0.01

    A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in…

  • CVE-2025-45471HigMay 22, 2025
    risk 0.57cvss 8.8epss 0.00

    Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cloud account.

  • CVE-2025-32813HigMay 22, 2025
    risk 0.50cvss 7.2epss 0.44

    An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.

  • CVE-2025-0993HigMay 22, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.

  • CVE-2025-5078HigMay 22, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was detected in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /admin/subcategory.php. Performing manipulation of the argument Category results in sql injection. The attack is possible to be carried out remotely. The…

  • CVE-2025-5077HigMay 22, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit-subcategory.php. The manipulation of the argument Category leads to sql injection. It is possible to initiate the attack…

  • CVE-2025-5076HigMay 22, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this issue is some unknown functionality of the component SEND Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been…

  • CVE-2025-5075HigMay 22, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component DEBUG Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit…

  • CVE-2025-46714HigMay 22, 2025
    risk 0.51cvss 7.8epss 0.00

    Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to 1.15.12, API_GET_SECURE_PARAM has an arithmetic overflow leading to a small memory allocation and then a extremely large copy into the…

  • CVE-2025-46713HigMay 22, 2025
    risk 0.51cvss 7.8epss 0.00

    Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 0.0.1 and prior to 1.15.12, API_SET_SECURE_PARAM may have an arithmetic overflow deep in the memory allocation subsystem that would lead to a smaller…

  • CVE-2025-3945HigMay 22, 2025
    risk 0.47cvss 7.2epss 0.01

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows Command Delimiters. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before…

  • CVE-2025-3944HigMay 22, 2025
    risk 0.47cvss 7.2epss 0.01

    Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise…

  • CVE-2025-3937HigMay 22, 2025
    risk 0.50cvss 7.7epss 0.00

    Use of Password Hash With Insufficient Computational Effort vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1,…

  • CVE-2025-2272HigMay 22, 2025
    risk 0.46cvss 7.0epss 0.00

    Uncontrolled Search Path Element vulnerability in Forcepoint FIE Endpoint allows Privilege Escalation, Code Injection, Hijacking a privileged process.This issue affects FIE Endpoint: before 25.05.

  • CVE-2025-5074HigMay 22, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component PROMPT Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2025-5073HigMay 22, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. This issue affects some unknown processing of the component MKDIR Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-41403HigMay 22, 2025
    risk 0.54cvss 8.3epss 0.02

    Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data.

  • CVE-2025-3836HigMay 22, 2025
    risk 0.54cvss 8.3epss 0.06

    Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report.

  • CVE-2024-25010HigMay 22, 2025
    risk 0.57cvss 8.8epss 0.00

    Ericsson RAN Compute and Site Controller 6610 contains in certain configurations a high severity vulnerability where improper input validation could be exploited leading to arbitrary code execution.

  • CVE-2025-4123HigMay 22, 2025
    risk 0.53cvss 7.6epss 0.97

    A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not…

  • CVE-2025-3887HigMay 22, 2025
    risk 0.57cvss 8.8epss 0.01

    GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but…

  • CVE-2025-3884HigMay 22, 2025
    risk 0.49cvss 7.5epss 0.02

    Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cloudera Hue. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2025-3883HigMay 22, 2025
    risk 0.57cvss 8.8epss 0.01

    eCharge Hardy Barth cPH2 index.php Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of eCharge Hardy Barth cPH2 charging stations. Authentication is not required to…

  • CVE-2025-3882HigMay 22, 2025
    risk 0.57cvss 8.8epss 0.01

    eCharge Hardy Barth cPH2 nwcheckexec.php dest Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of eCharge Hardy Barth cPH2 charging stations. Authentication is not…

  • CVE-2025-3881HigMay 22, 2025
    risk 0.57cvss 8.8epss 0.01

    eCharge Hardy Barth cPH2 check_req.php ntp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of eCharge Hardy Barth cPH2 charging stations. Authentication is not…

  • CVE-2025-3486HigMay 22, 2025
    risk 0.57cvss 8.8epss 0.02

    Allegra isZipEntryValide Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is required to exploit this vulnerability. The specific flaw exists within…

  • CVE-2025-3483HigMay 22, 2025
    risk 0.51cvss 7.8epss 0.01

    MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MedDream PACS Server. Authentication is not required to exploit this…

  • CVE-2025-3482HigMay 22, 2025
    risk 0.51cvss 7.8epss 0.01

    MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MedDream PACS Server. Authentication is not required to exploit this…

  • CVE-2025-3481HigMay 22, 2025
    risk 0.51cvss 7.8epss 0.01

    MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MedDream PACS Server. Authentication is not required to exploit this…

  • CVE-2025-2759HigMay 22, 2025
    risk 0.51cvss 7.8epss 0.00

    GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of GStreamer. An attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2025-34025HigMay 21, 2025
    risk 0.57cvss 8.8epss 0.01

    The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerability caused by unsafe default mounting of host binary paths that allow the container to modify host paths. The escape can be used to trigger remote code…

  • CVE-2025-5057HigMay 21, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/insert-product.php. The manipulation of the argument Category leads to sql injection. The attack may be…

  • CVE-2025-5056HigMay 21, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-products.php. The manipulation of the argument Category leads to sql injection. The attack can…