VYPR

CVEs

116,623 total · page 697 of 2,333

  • CVE-2025-34026HigKEVMay 21, 2025
    risk 0.67cvss 7.5epss 0.82

    The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace…

  • CVE-2025-5053HigMay 21, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is some unknown functionality of the component MDIR Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit…

  • CVE-2025-5052HigMay 21, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unknown functionality of the component LS Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been…

  • CVE-2025-45753HigMay 21, 2025
    risk 0.47cvss 7.2epss 0.00

    A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature.

  • CVE-2025-44040HigMay 21, 2025
    risk 0.47cvss 7.2epss 0.00

    An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication decisions may be made via PHP loose-equality comparisons if a specific MD5 value is present in the credential store. NOTE: this is disputed…

  • CVE-2025-5051HigMay 21, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component BINARY Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to…

  • CVE-2025-5050HigMay 21, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in FreeFloat FTP Server 1.0. It has been rated as critical. This issue affects some unknown processing of the component BELL Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed…

  • CVE-2025-5049HigMay 21, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. This vulnerability affects unknown code of the component APPEND Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been…

  • CVE-2025-45752HigMay 21, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the zip import functionality in the Extension Manager.

  • CVE-2025-3751HigMay 21, 2025
    risk 0.46cvss epss 0.00

    The component listed above contains a vulnerability that can be exploited by an attacker to perform a SQL Injection attack. This could lead to unauthorised access to the database and exposure of sensitive information

  • CVE-2025-2261HigMay 21, 2025
    risk 0.46cvss epss 0.00

    Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within user's browser under the privileges of the web application.

  • CVE-2025-48063HigMay 21, 2025
    risk 0.50cvss 8.8epss 0.01

    XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a document can have. Part of the security model of required rights is that a user who doesn't have a right also cannot define that right as required right. That…

  • CVE-2025-48060HigMay 21, 2025
    risk 0.49cvss 7.5epss 0.01

    jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in function `jv_string_vfmt` in the jq_fuzz_execute harness from oss-fuzz. This crash happens on file jv.c, line 1456 `void* p = malloc(sz);`. As of time of publication,…

  • CVE-2025-47291HigMay 21, 2025
    risk 0.49cvss 7.5epss 0.00

    containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under the Kubernetes' cgroup hierarchy, therefore some Kubernetes…

  • CVE-2025-46822HigMay 21, 2025
    risk 0.46cvss epss 0.04

    OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path traversal possible. This vulnerability…

  • CVE-2025-5032HigMay 21, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /admin/edit-category.php. The manipulation of the argument Category leads to sql injection. It is possible to launch the attack remotely.…

  • CVE-2025-4416HigMay 21, 2025
    risk 0.49cvss 7.5epss 0.00

    Allocation of Resources Without Limits or Throttling vulnerability in Drupal Events Log Track allows Excessive Allocation.This issue affects Events Log Track: from 0.0.0 before 3.1.11, from 4.0.0 before 4.0.2.

  • CVE-2025-20152HigMay 21, 2025
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain…

  • CVE-2025-20113HigMay 21, 2025
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges to Administrator for a limited set of functions on an affected system. This vulnerability is due to insufficient server-side validation of user-supplied…

  • CVE-2025-4008HigKEVMay 21, 2025
    risk 0.77cvss 8.8epss 0.93

    The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command…

  • CVE-2025-48207HigMay 21, 2025
    risk 0.49cvss 8.6epss 0.00

    The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.

  • CVE-2025-48205HigMay 21, 2025
    risk 0.56cvss 8.6epss 0.00

    The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.

  • CVE-2025-48201HigMay 21, 2025
    risk 0.49cvss 8.6epss 0.00

    The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.

  • CVE-2025-27998HigMay 21, 2025
    risk 0.55cvss 8.4epss 0.00

    An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted executable or DLL.

  • CVE-2025-27997HigMay 21, 2025
    risk 0.55cvss 8.4epss 0.00

    An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\ProgramData directory.

  • CVE-2024-56429HigMay 21, 2025
    risk 0.50cvss 7.7epss 0.00

    itech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users to read or write to the database.

  • CVE-2025-48416HigMay 21, 2025
    risk 0.53cvss 8.1epss 0.01

    An OpenSSH daemon listens on TCP port 22. There is a hard-coded entry in the "/etc/shadow" file in the firmware image for the "root" user. However, in the default SSH configuration the "PermitRootLogin" is disabled, preventing the root user from logging in via SSH. This…

  • CVE-2025-40775HigMay 21, 2025
    risk 0.50cvss 7.5epss 0.15

    When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.8 and…

  • CVE-2025-1416HigMay 21, 2025
    risk 0.46cvss epss 0.00

    In Proget MDM, a low-privileged user can retrieve passwords for managed devices and subsequently use functionalities restricted by the MDM (Mobile Device Management). For it to happen, they must know the UUIDs of targetted devices, which might be obtained by…

  • CVE-2025-4803HigMay 21, 2025
    risk 0.47cvss 7.2epss 0.01

    The Glossary by WPPedia – Best Glossary plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.0 via deserialization of untrusted input from the 'posttypes' parameter. This makes it possible for authenticated…

  • CVE-2025-48413HigMay 21, 2025
    risk 0.50cvss 7.7epss 0.00

    The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The credentials are shipped with the update files. There is no option for deleting or changing their passwords for an enduser. An attacker can use the credentials to…

  • CVE-2025-1712HigMay 21, 2025
    risk 0.57cvss 8.8epss 0.01

    Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticated attackers to write arbitrary files

  • CVE-2019-16536HigMay 21, 2025
    risk 0.50cvss 8.8epss 0.01

    Stack overflow leading to DoS can be triggered by a malicious authenticated client in Clickhouse before 19.14.3.3.

  • CVE-2021-25255HigMay 21, 2025
    risk 0.49cvss 7.5epss 0.01

    Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.

  • CVE-2025-5008HigMay 20, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in projectworlds Online Time Table Generator 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_teacher.php. The manipulation of the argument e leads to sql injection. The attack may be…

  • CVE-2025-5006HigMay 20, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/category.php. The manipulation of the argument Category leads to sql injection. It is possible to launch the attack remotely.…

  • CVE-2025-5004HigMay 20, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in projectworlds Online Time Table Generator 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/add_course.php. The manipulation of the argument c/subname leads to sql injection. The attack may be initiated…

  • CVE-2025-5003HigMay 20, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in projectworlds Online Time Table Generator 1.0 and classified as critical. This vulnerability affects unknown code of the file /semester_ajax.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely.…

  • CVE-2025-5002HigMay 20, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_proposal_update_order.php. The manipulation of the argument order_id leads to sql injection. It is possible to…

  • CVE-2025-4364HigMay 20, 2025
    risk 0.57cvss epss 0.00

    The affected products could allow an unauthenticated attacker to access system information that could enable further access to sensitive files and obtain administrative credentials.

  • CVE-2025-48391HigMay 20, 2025
    risk 0.50cvss 7.7epss 0.00

    In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API

  • CVE-2025-37991HigMay 20, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: parisc: Fix double SIGFPE crash Camm noticed that on parisc a SIGFPE exception will crash an application with a second SIGFPE in the signal handler. Dave analyzed it, and it happens because glibc uses a…

  • CVE-2025-37988HigMay 20, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: fix a couple of races in MNT_TREE_BENEATH handling by do_move_mount() Normally do_lock_mount(path, _) is locking a mountpoint pinned by *path and at the time when matching unlock_mount() unlocks that location…

  • CVE-2025-37984HigMay 20, 2025
    risk 0.46cvss 7.0epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP() Herbert notes that DIV_ROUND_UP() may overflow unnecessarily if an ecdsa implementation's ->key_size() callback returns an unusually large…

  • CVE-2025-22157HigMay 20, 2025
    risk 0.57cvss 8.8epss 0.01

    This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server 5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service Management Data Center and Server This PrivEsc (Privilege…

  • CVE-2025-37981HigMay 20, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Use is_kdump_kernel() to check for kdump The smartpqi driver checks the reset_devices variable to determine whether special adjustments need to be made for kdump. This has the effect that after…

  • CVE-2025-37979HigMay 20, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix sc7280 lpass potential buffer overflow Case values introduced in commit 5f78e1fb7a3e ("ASoC: qcom: Add driver support for audioreach solution") cause out of bounds access in arrays of sc7280…

  • CVE-2025-37977HigMay 20, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: exynos: Disable iocc if dma-coherent property isn't set If dma-coherent property isn't set then descriptors are non-cacheable and the iocc shareability bits should be disabled. Without this UFS can…

  • CVE-2025-37975HigMay 20, 2025
    risk 0.46cvss 7.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: riscv: module: Fix out-of-bounds relocation access The current code allows rel[j] to access one element past the end of the relocation section. Simplify to num_relocations which is equivalent to the existing…

  • CVE-2025-37973HigMay 20, 2025
    risk 0.53cvss 8.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix out-of-bounds access during multi-link element defragmentation Currently during the multi-link element defragmentation process, the multi-link element length added to the total IEs length…