VYPR

CVEs

116,590 total · page 714 of 2,332

  • CVE-2025-4331HigMay 6, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in SourceCodester Online Student Clearance System 1.0. This vulnerability affects unknown code of the file /Admin/login.php. The manipulation of the argument id/username/password leads to sql injection. The attack can be initiated…

  • CVE-2025-46585HigMay 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Out-of-bounds array read/write vulnerability in the kernel module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-46584HigMay 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Vulnerability of improper authentication logic implementation in the file system module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-4314HigMay 6, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in SourceCodester Advanced Web Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation of the argument txtLogin leads to sql injection. The attack can be…

  • CVE-2025-4313HigMay 6, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Advanced Web Store 1.0. Affected is an unknown function of the file /admin/admin_addnew_product.php. The manipulation of the argument txtProdId leads to sql injection. It is possible to launch the…

  • CVE-2025-2802HigMay 6, 2025
    risk 0.47cvss 7.3epss 0.00

    The LayoutBoxx plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.3.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it…

  • CVE-2025-4312HigMay 6, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Advanced Web Store 1.0. This issue affects some unknown processing of the file /productdetail.php. The manipulation of the argument prodid leads to sql injection. The attack may be initiated…

  • CVE-2025-4311HigMay 6, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /admin/update_main_topic_img.php?topic_id=529. The manipulation of the argument stopic_id leads to sql injection. The attack can be…

  • CVE-2025-4309HigMay 6, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add-art-type.php. The manipulation of the argument arttype leads to sql injection. The attack may be…

  • CVE-2025-4308HigMay 6, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add-art-type.php. The manipulation of the argument arttype leads to sql injection. The…

  • CVE-2025-4307HigMay 6, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been classified as critical. Affected is an unknown function of the file /admin/add-art-medium.php. The manipulation of the argument artmed leads to sql injection. It is possible to launch the…

  • CVE-2025-4306HigMay 6, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /edit-phlebotomist.php. The manipulation of the argument mobilenumber leads to sql injection. The attack may be…

  • CVE-2025-3610HigMay 6, 2025
    risk 0.57cvss 8.8epss 0.01

    The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.1.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it…

  • CVE-2025-4304HigMay 6, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in PHPGurukul Cyber Cafe Management System 1.0. This affects an unknown part of the file /adminprofile.php. The manipulation of the argument mobilenumber leads to sql injection. It is possible to initiate the attack…

  • CVE-2025-4303HigMay 6, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /add-phlebotomist.php. The manipulation of the argument empid leads to sql…

  • CVE-2025-4301HigMay 6, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in itsourcecode Content Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search-notice.php. The manipulation of the argument searchdata leads to sql injection. The attack can be…

  • CVE-2025-46728HigMay 6, 2025
    risk 0.00cvss 7.5epss 0.01

    cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to version 0.20.1, the library fails to enforce configured size limits on incoming request bodies when `Transfer-Encoding: chunked` is used or when no `Content-Length` header is provided. A remote…

  • CVE-2025-2509HigMay 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via crafted vertex elements data triggering an out-of-bounds read in…

  • CVE-2025-4300HigMay 6, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. Affected is an unknown function of the file /search_list.php. The manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2025-4299HigMay 6, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been rated as critical. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-4298HigMay 6, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been declared as critical. This vulnerability affects the function formSetCfm of the file /goform/setcfm. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been…

  • CVE-2025-4297HigMay 5, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Men Salon Management System 2.0. It has been classified as critical. This affects an unknown part of the file /admin/change-password.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit…

  • CVE-2025-4290HigMay 5, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component SMNT Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-4289HigMay 5, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of the component RNTO Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the…

  • CVE-2025-4288HigMay 5, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component RNFR Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the…

  • CVE-2025-46731HigMay 5, 2025
    risk 0.40cvss 7.2epss 0.01

    Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be…

  • CVE-2025-45617HigMay 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload.

  • CVE-2025-45614HigMay 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information via a crafted payload.

  • CVE-2025-45613HigMay 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive information via a crafted payload.

  • CVE-2025-45610HigMay 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sensitive information via a crafted payload.

  • CVE-2025-45609HigMay 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive information via a crafted payload.

  • CVE-2025-45608HigMay 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload.

  • CVE-2025-4283HigMay 5, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Login.php?f=login. The manipulation of the argument Username leads to sql injection. The attack may be…

  • CVE-2025-4279HigMay 5, 2025
    risk 0.57cvss 8.8epss 0.01

    The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'external_image_replace_get_posts::replace_post' function in all versions up to, and including, 1.0.8. This makes it possible for authenticated…

  • CVE-2025-46340HigMay 5, 2025
    risk 0.00cvss 7.2epss 0.00

    Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, due to an oversight in the validation performed in `UrlPreviewService` and `MkUrlPreview`, it is possible for an attacker to inject arbitrary CSS into the…

  • CVE-2025-4096HigMay 5, 2025
    risk 0.57cvss 8.8epss 0.00

    Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-4050HigMay 5, 2025
    risk 0.57cvss 8.8epss 0.00

    Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2025-45237HigMay 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.

  • CVE-2025-45242HigMay 5, 2025
    risk 0.50cvss 7.7epss 0.00

    Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method in /file/file.admin.controller.php.

  • CVE-2025-0217HigMay 5, 2025
    risk 0.51cvss 7.8epss 0.00

    BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to…

  • CVE-2025-45322HigMay 5, 2025
    risk 0.57cvss 8.8epss 0.00

    kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the checkid parameter.

  • CVE-2025-45321HigMay 5, 2025
    risk 0.57cvss 8.8epss 0.00

    kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.php via the parameter: rPassword.

  • CVE-2025-28062HigMay 5, 2025
    risk 0.56cvss 8.1epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.

  • CVE-2025-27920HigKEVMay 5, 2025
    risk 0.59cvss 7.2epss 0.02

    Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or…

  • CVE-2024-58237HigMay 5, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: bpf: consider that tail calls invalidate packet pointers Tail-called programs could execute any of the helpers that invalidate packet pointers. Hence, conservatively assume that each tail call invalidates…

  • CVE-2024-58100HigMay 5, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: bpf: check changes_pkt_data property for extension programs When processing calls to global sub-programs, verifier decides whether to invalidate all packet pointers in current state depending on the…

  • CVE-2024-58098HigMay 5, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: bpf: track changes_pkt_data property for global functions When processing calls to certain helpers, verifier invalidates all packet pointers in a current state. For example, consider the following program: …

  • CVE-2025-4272HigMay 5, 2025
    risk 0.46cvss 7.0epss 0.00

    A vulnerability was found in Mechrevo Control Console 1.0.2.70. It has been rated as critical. Affected by this issue is some unknown functionality in the library C:\Program Files\OEM\MECHREVO Control Center\UniwillService\MyControlCenter\csCAPI.dll of the component GCUService.…

  • CVE-2025-4266HigMay 5, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability, which was classified as critical, has been found in PHPGurukul Notice Board System 1.0. Affected by this issue is some unknown functionality of the file /bwdates-reports-details.php?vid=2. The manipulation of the argument fromdate/tomdate leads to sql injection.…

  • CVE-2025-4265HigMay 5, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/contact-us.php. The manipulation of the argument mobnum leads to sql injection. The attack can be…