VYPR

CVEs

116,603 total · page 705 of 2,333

  • CVE-2025-47445HigMay 14, 2025
    risk 0.49cvss 7.5epss 0.05

    Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.26.

  • CVE-2025-3931HigMay 14, 2025
    risk 0.44cvss 7.8epss 0.00

    A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and…

  • CVE-2025-4430HigMay 14, 2025
    risk 0.56cvss epss 0.00

    Unauthorized access to "/api/Token/gettoken" endpoint in EZD RP allows file manipulation.This issue affects EZD RP in versions before 20.19 (published on 22nd August 2024).

  • CVE-2025-3834HigMay 14, 2025
    risk 0.53cvss 8.1epss 0.02

    Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.

  • CVE-2025-3833HigMay 14, 2025
    risk 0.55cvss 8.1epss 0.45

    Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.

  • CVE-2025-26864HigMay 14, 2025
    risk 0.42cvss 7.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB. This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are recommended…

  • CVE-2025-26795HigMay 14, 2025
    risk 0.42cvss 7.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are recommended to upgrade to…

  • CVE-2025-2875HigMay 14, 2025
    risk 0.49cvss 7.5epss 0.00

    CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality when an unauthenticated attacker manipulates controller’s webserver URL to access resources.

  • CVE-2025-26646HigMay 13, 2025
    risk 0.52cvss 8.0epss 0.01

    External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.

  • CVE-2025-43572HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-43571HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-43570HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-43569HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-43568HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-43565HigMay 13, 2025
    risk 0.55cvss 8.4epss 0.16

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security…

  • CVE-2025-43554HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Modeler versions 1.21.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2025-43553HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Modeler versions 1.21.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. If the application relies on a search path to locate critical resources such as…

  • CVE-2025-43549HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-43548HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-24308HigMay 13, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper input validation in the UEFI firmware error handler for the Intel(R) Server D50DNP and M50FCP may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2025-22843HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-21094HigMay 13, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper input validation in the UEFI firmware DXE module for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2025-20618HigMay 13, 2025
    risk 0.51cvss 7.9epss 0.00

    Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2025-20104HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Race condition in some Administrative Tools for some Intel(R) Network Adapters package before version 29.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-20101HigMay 13, 2025
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds read for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable information disclosure or denial of service via local access.

  • CVE-2025-20100HigMay 13, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper access control in the memory controller configurations for some Intel(R) Xeon(R) 6 processor with E-cores may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2025-20083HigMay 13, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper authentication in the firmware for the Intel(R) Slim Bootloader may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2025-20082HigMay 13, 2025
    risk 0.49cvss 7.5epss 0.00

    Time-of-check time-of-use race condition in the UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to enable escalation of privilege via local access.

  • CVE-2025-20052HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper access control for some Intel(R) Graphics software may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2025-20046HigMay 13, 2025
    risk 0.52cvss 8.0epss 0.00

    Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2025-20032HigMay 13, 2025
    risk 0.51cvss 7.9epss 0.00

    Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2025-20018HigMay 13, 2025
    risk 0.55cvss 8.4epss 0.00

    Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-20008HigMay 13, 2025
    risk 0.50cvss 7.7epss 0.00

    Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2025-20006HigMay 13, 2025
    risk 0.48cvss 7.4epss 0.00

    Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2025-20004HigMay 13, 2025
    risk 0.47cvss 7.2epss 0.00

    Insufficient control flow management in the Alias Checking Trusted Module for some Intel(R) Xeon(R) 6 processor E-Cores firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2025-20003HigMay 13, 2025
    risk 0.53cvss 8.2epss 0.00

    Improper link resolution before file access ('Link Following') for some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-45333HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper access control for some Intel(R) Data Center GPU Flex Series for Windows driver before version 31.0.101.4314 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2024-36292HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper buffer restrictions for some Intel(R) Data Center GPU Flex Series for Windows driver before version 31.0.101.4314 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2025-3744HigMay 13, 2025
    risk 0.49cvss 7.6epss 0.00

    Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.

  • CVE-2025-43557HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Animate versions 24.0.8, 23.0.11 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-43556HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-43555HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open…

  • CVE-2025-43547HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-43546HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-43545HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-30330HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Illustrator versions 29.3, 28.7.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2025-30328HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Animate versions 24.0.8, 23.0.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-30326HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open…

  • CVE-2025-30325HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open…

  • CVE-2025-30324HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…