VYPR

CVEs

116,583 total · page 719 of 2,332

  • CVE-2025-2082HigApr 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Tesla Model 3 VCSEC Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 vehicles. Authentication is not required to exploit this vulnerability. The specific flaw exists…

  • CVE-2025-27611HigApr 30, 2025
    risk 0.50cvss epss 0.00

    base-x is a base encoder and decoder of any given alphabet using bitcoin style leading zero compression. Versions 4.0.0, 5.0.0, and all prior to 3.0.11, are vulnerable to attackers potentially deceiving users into sending funds to an unintended address. This issue has been…

  • CVE-2024-6032HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.01

    Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code on the target system in order to…

  • CVE-2024-6031HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Tesla Model S oFono AT Command Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code on the target modem in order…

  • CVE-2024-6030HigApr 30, 2025
    risk 0.46cvss 7.0epss 0.00

    Tesla Model S oFono Unnecessary Privileges Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code within the sandbox on the target system in order…

  • CVE-2024-13943HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected affected Tesla Model S vehicles. An attacker must first obtain the ability to execute…

  • CVE-2025-32777HigApr 30, 2025
    risk 0.46cvss epss 0.00

    Volcano is a Kubernetes-native batch scheduling system. Prior to versions 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology-preview.3, and 1.12.0-alpha.2, attacker compromise of either the Elastic service or the extender plugin can cause denial of service of the scheduler. This is…

  • CVE-2025-2170HigApr 30, 2025
    risk 0.47cvss 7.2epss 0.00

    A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions could potentially enable a remote unauthenticated attacker to cause the appliance to make requests to an unintended location.

  • CVE-2024-9876HigApr 30, 2025
    risk 0.47cvss 7.3epss 0.00

    : Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.

  • CVE-2025-46619HigApr 30, 2025
    risk 0.49cvss 7.6epss 0.00

    A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or…

  • CVE-2025-44194HigApr 30, 2025
    risk 0.47cvss 7.3epss 0.00

    SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_household.

  • CVE-2025-44193HigApr 30, 2025
    risk 0.49cvss 7.6epss 0.00

    SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_complaint.

  • CVE-2025-33074HigApr 30, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network.

  • CVE-2025-30391HigApr 30, 2025
    risk 0.53cvss 8.1epss 0.01

    Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-30389HigApr 30, 2025
    risk 0.57cvss 8.7epss 0.01

    Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-21416HigApr 30, 2025
    risk 0.55cvss 8.5epss 0.01

    Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-46342HigApr 30, 2025
    risk 0.48cvss 8.5epss 0.01

    Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.13.5 and 1.14.0, it may happen that policy rules using namespace selector(s) in their match statements are mistakenly not applied during admission review request processing due…

  • CVE-2025-27409HigApr 30, 2025
    risk 0.00cvss 7.5epss 0.01

    Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, path traversal is possible in Joplin Server if static file path starts with `css/pluginAssets` or `js/pluginAssets`. The…

  • CVE-2025-27134HigApr 30, 2025
    risk 0.00cvss 8.8epss 0.02

    Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, a privilege escalation vulnerability exists in the Joplin server, allowing non-admin users to exploit the API endpoint…

  • CVE-2025-4120HigApr 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been classified as critical. Affected is the function sub_4238E8. The manipulation of the argument host leads to buffer overflow. It is possible to launch the attack remotely. The vendor was contacted early about…

  • CVE-2025-4116HigApr 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, has been found in Netgear JWNR2000v2 1.0.0.11. Affected by this issue is the function get_cur_lang_ver. The manipulation of the argument host leads to buffer overflow. The attack may be launched remotely. The vendor was…

  • CVE-2025-4115HigApr 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical was found in Netgear JWNR2000v2 1.0.0.11. Affected by this vulnerability is the function default_version_is_new. The manipulation of the argument host leads to buffer overflow. The attack can be launched remotely. The vendor was contacted…

  • CVE-2025-45020HigApr 30, 2025
    risk 0.47cvss 7.2epss 0.01

    A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the todate parameter in a POST request.

  • CVE-2025-3395HigApr 30, 2025
    risk 0.46cvss 7.1epss 0.00

    Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.

  • CVE-2025-3394HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.

  • CVE-2025-4114HigApr 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical has been found in Netgear JWNR2000v2 1.0.0.11. Affected is the function check_language_file. The manipulation of the argument host leads to buffer overflow. It is possible to launch the attack remotely. The vendor was contacted early about…

  • CVE-2025-24351HigApr 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the “Remote Logging” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to execute arbitrary OS commands in the context of user “root” via a crafted HTTP request.

  • CVE-2025-24350HigApr 30, 2025
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the “Certificates and Keys” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to write arbitrary certificates in arbitrary file system paths via a crafted HTTP request.

  • CVE-2025-24349HigApr 30, 2025
    risk 0.46cvss 7.1epss 0.01

    A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) attacker to delete the configuration of physical network interfaces via a crafted HTTP request.

  • CVE-2025-24346HigApr 30, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the “Proxy” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) attacker to manipulate the “/etc/environment” file via a crafted HTTP request.

  • CVE-2025-4112HigApr 30, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Student Record System 3.20. It has been declared as critical. This vulnerability affects unknown code of the file /add-course.php. The manipulation of the argument course-short leads to sql injection. The attack can be initiated remotely.…

  • CVE-2025-24338HigApr 30, 2025
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) attacker to execute arbitrary client-side code in the context of another user's browser via multiple crafted HTTP requests.

  • CVE-2025-4108HigApr 30, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an unknown function of the file /add-subject.php. The manipulation of the argument sub1 leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2025-4125HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing ISP file.

  • CVE-2025-4124HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing ISP file.

  • CVE-2025-22884HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.

  • CVE-2025-22883HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.

  • CVE-2025-22882HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to leverage debugging logic to execute arbitrary code when parsing CBDGL file.

  • CVE-2025-30202HigApr 30, 2025
    risk 0.42cvss 7.5epss 0.01

    vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.5.2 and prior to 0.8.5 are vulnerable to denial of service and data exposure via ZeroMQ on multi-node vLLM deployment. In a multi-node vLLM deployment, vLLM uses ZeroMQ…

  • CVE-2025-29906HigApr 29, 2025
    risk 0.49cvss 8.6epss 0.00

    Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authentication. This issue has been…

  • CVE-2025-3501HigApr 29, 2025
    risk 0.46cvss 8.2epss 0.00

    A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

  • CVE-2024-57698HigApr 29, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without authentication, even after initial configuration and password change. This happens due to excessive exposure of information and the lack of adequate access…

  • CVE-2025-4079HigApr 29, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in PCMan FTP Server up to 2.0.7. Affected is an unknown function of the component RENAME Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2025-4074HigApr 29, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/pass-bwdates-report.php. The manipulation of the argument fromdate/todate leads to sql…

  • CVE-2025-46349HigApr 29, 2025
    risk 0.42cvss 7.6epss 0.01

    YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file upload form. This vulnerability allows any malicious unauthenticated user to create a link that can be clicked on by the victim to perform arbitrary actions. This…

  • CVE-2025-4073HigApr 29, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Student Record System 3.20. It has been classified as critical. Affected is an unknown function of the file /change-password.php. The manipulation of the argument currentpassword leads to sql injection. It is possible to launch the attack…

  • CVE-2025-45956HigApr 29, 2025
    risk 0.57cvss 8.8epss 0.00

    A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows an authenticated attacker to execute arbitrary SQL commands via the "id" parameter

  • CVE-2025-23181HigApr 29, 2025
    risk 0.52cvss 8.0epss 0.00

    CWE-250: Execution with Unnecessary Privileges

  • CVE-2025-23180HigApr 29, 2025
    risk 0.52cvss 8.0epss 0.00

    CWE-250: Execution with Unnecessary Privileges

  • CVE-2025-4071HigApr 29, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /test-details.php. The manipulation of the argument Status leads to sql injection. The attack can be initiated…