VYPR

CVEs

116,604 total · page 703 of 2,333

  • CVE-2025-4746HigMay 16, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pages/purchase_delete.php. The manipulation of the argument pr_id leads to sql injection. The attack can be initiated…

  • CVE-2025-4741HigMay 16, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /pages/purchase_add.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely.…

  • CVE-2025-4739HigMay 16, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in projectworlds Hospital Database Management System 1.0. It has been classified as critical. This affects an unknown part of the file /medicines_info.php. The manipulation of the argument Med_ID leads to sql injection. It is possible to initiate the…

  • CVE-2025-4736HigMay 16, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Daily Expense Tracker 1.1 and classified as critical. Affected by this issue is some unknown functionality of the file /register.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The…

  • CVE-2025-4734HigMay 16, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in Campcodes Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/ci_update.php. The manipulation of the argument id/name leads to sql injection. It is possible to launch the attack…

  • CVE-2025-4733HigMay 16, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processing of the file /boafrm/formIpQoS of the component HTTP POST Request Handler. The manipulation of the argument mac leads…

  • CVE-2025-4732HigMay 16, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability affects unknown code of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument ip6addr leads to buffer…

  • CVE-2025-47809HigMay 16, 2025
    risk 0.53cvss 8.2epss 0.00

    Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the…

  • CVE-2025-4731HigMay 16, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument service_type/ip_subnet leads to…

  • CVE-2025-4730HigMay 16, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formMapDel of the component HTTP POST Request Handler. The manipulation of the argument…

  • CVE-2025-4728HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Best Online News Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /search.php. The manipulation of the argument searchtitle leads to sql injection. It is possible to launch the attack…

  • CVE-2025-4726HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in itsourcecode Placement Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /view_student.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The…

  • CVE-2025-4725HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in itsourcecode Placement Management System 1.0. This affects an unknown part of the file /view_drive.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The…

  • CVE-2025-4724HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in itsourcecode Placement Management System 1.0. Affected by this issue is some unknown functionality of the file /student_profile.php. The manipulation of the argument ID leads to sql injection. The attack may be…

  • CVE-2025-4723HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /all_student.php. The manipulation of the argument delete leads to sql injection. The attack can be launched…

  • CVE-2025-4722HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file /edit_profile.php. The manipulation of the argument Name leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2025-47287HigMay 15, 2025
    risk 0.42cvss 7.5epss 0.01

    Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high…

  • CVE-2025-4721HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /drive.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The…

  • CVE-2025-4719HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/cash_transaction.php. The manipulation of the argument cid leads to sql injection. The attack may be launched…

  • CVE-2025-4718HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pages/customer_add.php. The manipulation of the argument last leads to sql injection. The attack can be…

  • CVE-2025-4717HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 2.0. Affected is an unknown function of the file /visitors-form.php. The manipulation of the argument fullname leads to sql injection. It is possible to launch the attack…

  • CVE-2025-4716HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pages/credit_transaction_add.php. The manipulation of the argument prod_name leads to sql injection. The attack…

  • CVE-2025-4715HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /pages/view_application.php. The manipulation of the argument cid leads to sql injection. The attack…

  • CVE-2025-47785HigMay 15, 2025
    risk 0.54cvss 8.3epss 0.01

    Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is not strictly filtered. Since admin/article_save.php can be accessed by ordinary registered users, this…

  • CVE-2025-47161HigMay 15, 2025
    risk 0.54cvss 7.8epss 0.01

    Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

  • CVE-2024-9831HigMay 15, 2025
    risk 0.47cvss 7.2epss 0.01

    The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

  • CVE-2024-8700HigMay 15, 2025
    risk 0.49cvss 7.5epss 0.00

    The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.

  • CVE-2024-8699HigMay 15, 2025
    risk 0.47cvss 7.2epss 0.01

    The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

  • CVE-2024-6719HigMay 15, 2025
    risk 0.53cvss 8.1epss 0.00

    The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack

  • CVE-2024-6486HigMay 15, 2025
    risk 0.47cvss 7.2epss 0.02

    The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server…

  • CVE-2024-12812HigMay 15, 2025
    risk 0.49cvss 7.5epss 0.01

    The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDOR issue where employees can manipulate parameters to access the data of terminated employees.

  • CVE-2024-12735HigMay 15, 2025
    risk 0.47cvss 7.2epss 0.01

    The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins and above to perform SQL injection attacks

  • CVE-2024-11372HigMay 15, 2025
    risk 0.47cvss 7.2epss 0.01

    The Connexion Logs WordPress plugin through 3.0.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

  • CVE-2024-11269HigMay 15, 2025
    risk 0.47cvss 7.2epss 0.01

    The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statement, allowing Admin to perform SQL injection attacks.

  • CVE-2024-11267HigMay 15, 2025
    risk 0.57cvss 8.8epss 0.01

    The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks.

  • CVE-2024-0852HigMay 15, 2025
    risk 0.57cvss 8.8epss 0.01

    The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting it back in the admin dashboard, allowing unauthenticated users to perform Stored XSS attack against high privilege users such as admin

  • CVE-2024-0249HigMay 15, 2025
    risk 0.46cvss 7.1epss 0.00

    The Advanced Schedule Posts WordPress plugin through 2.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins.

  • CVE-2023-7239HigMay 15, 2025
    risk 0.49cvss 7.5epss 0.01

    The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id parameter in its wpdn_update_note AJAX action. This allows users with a role of contributor and above to update notes created by other users.

  • CVE-2023-7231HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.00

    The illi Link Party! WordPress plugin through 1.0 lacks proper access controls, allowing unauthenticated visitors to delete links.

  • CVE-2023-7197HigMay 15, 2025
    risk 0.46cvss 7.1epss 0.00

    The Marketing Twitter Bot WordPress plugin through 1.11 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

  • CVE-2023-7174HigMay 15, 2025
    risk 0.46cvss 7.1epss 0.00

    The aBitGone CommentSafe WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

  • CVE-2023-5934HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.00

    The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.13 does not have CSRF check in place when importing settings from the v1, which could allow attackers to make a logged in admin update some settings via a CSRF attack

  • CVE-2025-4714HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file /pages/reprint.php. The manipulation of the argument sid leads to sql injection. It is possible to launch the attack remotely.…

  • CVE-2025-4713HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/print.php. The manipulation of the argument sid leads to sql injection. The attack may be initiated remotely. The…

  • CVE-2025-4712HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pages/account_summary.php. The manipulation of the argument cid leads to sql injection. The attack can be initiated…

  • CVE-2025-32922HigMay 15, 2025
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Stored XSS.This issue affects WP2LEADS: from n/a through <= 3.5.0.

  • CVE-2025-30475HigMay 15, 2025
    risk 0.53cvss 8.1epss 0.00

    Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.

  • CVE-2025-26481HigMay 15, 2025
    risk 0.49cvss 7.5epss 0.00

    Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2025-4711HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /pages/stockin_add.php. The manipulation of the argument prod_name leads to sql injection. It is possible to initiate the attack…

  • CVE-2025-4710HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Campcodes Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/transaction.php. The manipulation of the argument cid leads to sql injection. The attack may be…