VYPR

CVEs

116,583 total · page 721 of 2,332

  • CVE-2025-3990HigApr 27, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, has been found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this issue is some unknown functionality of the file /boafrm/formVlan. The manipulation of the argument submit-url leads to buffer overflow. The attack may be…

  • CVE-2025-3989HigApr 27, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical was found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this vulnerability is an unknown functionality of the file /boafrm/formStaticDHCP. The manipulation of the argument Hostname leads to buffer overflow. The attack can be launched…

  • CVE-2025-3988HigApr 27, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. Affected is an unknown function of the file /boafrm/formPortFw. The manipulation of the argument service_type leads to buffer overflow. It is possible to launch the attack remotely. The…

  • CVE-2025-46657HigApr 27, 2025
    risk 0.47cvss 7.2epss 0.00

    Karaz Karazal through 2025-04-14 allows reflected XSS via the lang parameter to the default URI.

  • CVE-2025-3976HigApr 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /new-user-testing.php. The manipulation of the argument mobilenumber leads to sql injection. It is possible to launch…

  • CVE-2025-3974HigApr 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit-phlebotomist.php?pid=11. The manipulation of the argument mobilenumber leads to sql injection. The attack can…

  • CVE-2025-3973HigApr 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability, which was classified as critical, was found in PHPGurukul COVID19 Testing Management System 1.0. This affects an unknown part of the file /check_availability.php. The manipulation of the argument mobnumber leads to sql injection. It is possible to initiate the…

  • CVE-2025-3972HigApr 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /bwdates-report-result.php. The manipulation of the argument todate leads to sql injection. The…

  • CVE-2025-3971HigApr 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical was found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-phlebotomist.php. The manipulation of the argument empid leads to sql injection. The attack can be…

  • CVE-2025-3886HigApr 27, 2025
    risk 0.53cvss 8.1epss 0.00

    An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component.

  • CVE-2025-3963HigApr 27, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in withstars Books-Management-System 1.0. This issue affects some unknown processing of the file /admin/article/list of the component Background Interface. The manipulation leads to missing authorization. The…

  • CVE-2025-3960HigApr 27, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in withstars Books-Management-System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /allreaders.html of the component Background Interface. The manipulation leads to missing authorization. The attack…

  • CVE-2025-46580HigApr 27, 2025
    risk 0.50cvss 7.7epss 0.00

    There is a code-related vulnerability in the GoldenDB database product. Attackers can access system tables to disrupt the normal operation of business SQL.

  • CVE-2025-46579HigApr 27, 2025
    risk 0.55cvss 8.4epss 0.00

    There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.

  • CVE-2025-2101HigApr 26, 2025
    risk 0.53cvss 8.1epss 0.01

    The Edumall theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.4 via the 'template' parameter of the 'edumall_lazy_load_template' AJAX action. This makes it possible for unauthenticated attackers to include and execute arbitrary…

  • CVE-2025-2851HigApr 26, 2025
    risk 0.52cvss 8.0epss 0.00

    A vulnerability classified as critical has been found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi,…

  • CVE-2025-3914HigApr 26, 2025
    risk 0.58cvss 8.8epss 0.15

    The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_media_downloader' function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with…

  • CVE-2025-3906HigApr 26, 2025
    risk 0.57cvss 8.8epss 0.00

    The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wep_opcoes' function in all versions up to, and including, 1.7.5. This makes it possible for authenticated attackers, with…

  • CVE-2025-3491HigApr 26, 2025
    risk 0.47cvss 7.2epss 0.01

    The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'acpt_validate_setting' function. This is due to insufficient sanitization of the 'template_name' parameter.…

  • CVE-2025-2105HigApr 26, 2025
    risk 0.53cvss 8.1epss 0.01

    The Jupiter X Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.8.11 via deserialization of untrusted input from the 'file' parameter of the 'raven_download_file' function. This makes it possible for attackers to inject a PHP…

  • CVE-2024-13808HigApr 26, 2025
    risk 0.57cvss 8.8epss 0.01

    The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.9 via the custom PHP widget. This is due to their only being client side controls when determining who can access the widget. This makes it…

  • CVE-2025-2801HigApr 26, 2025
    risk 0.47cvss 7.3epss 0.01

    The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.4. This is due to the software allowing users to execute an action that does not…

  • CVE-2025-46333HigApr 25, 2025
    risk 0.47cvss epss 0.00

    z2d is a pure Zig 2D graphics library. Versions of z2d after `0.5.1` and up to and including `0.6.0`, when writing from one surface to another using `z2d.compositor.StrideCompositor.run`, and higher-level operations when the anti-aliasing mode is set to `.default` (such as…

  • CVE-2025-32986HigApr 25, 2025
    risk 0.49cvss 7.5epss 0.00

    NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint.

  • CVE-2025-32983HigApr 25, 2025
    risk 0.49cvss 7.5epss 0.00

    NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.

  • CVE-2025-32982HigApr 25, 2025
    risk 0.49cvss 7.5epss 0.00

    NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.

  • CVE-2025-32981HigApr 25, 2025
    risk 0.46cvss 7.1epss 0.00

    NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.

  • CVE-2025-28128HigApr 25, 2025
    risk 0.46cvss 7.0epss 0.00

    An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a crafted request.

  • CVE-2025-3935HigKEVApr 25, 2025
    risk 0.65cvss 8.1epss 0.03

    ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys.  It is important to note that to obtain…

  • CVE-2025-3928HigKEVApr 25, 2025
    risk 0.69cvss 8.8epss 0.02

    Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89,…

  • CVE-2025-43862HigApr 25, 2025
    risk 0.00cvss 7.6epss 0.00

    Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even though the web UI of APP orchestration is not presented for a normal user. This access control flaw allows non-admin users to make…

  • CVE-2025-3642HigApr 25, 2025
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.

  • CVE-2025-3641HigApr 25, 2025
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.

  • CVE-2025-3638HigApr 25, 2025
    risk 0.50cvss 8.8epss 0.00

    A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.

  • CVE-2025-3625HigApr 25, 2025
    risk 0.46cvss 7.1epss 0.00

    A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).

  • CVE-2025-32044HigApr 25, 2025
    risk 0.42cvss 7.5epss 0.00

    A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with…

  • CVE-2023-32198higApr 25, 2025
    risk 0.45cvss epss 0.00

    ### Impact A vulnerability has been identified in Steve where by default it was using an insecure option that did not validate the certificate presented by the remote server while performing a TLS connection. This could allow the execution of a man-in-the-middle (MitM) attack…

  • CVE-2024-22031higApr 25, 2025
    risk 0.39cvss epss 0.01

    ### Impact A vulnerability has been identified within Rancher where a user with the ability to create a project, on a certain cluster, can create a project with the same name as an existing project in a different cluster. This results in the user gaining access to the other…

  • CVE-2024-6199HigApr 25, 2025
    risk 0.50cvss epss 0.00

    An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS services and the modem, could manipulate specific responses to include code that forces a buffer overflow on the modem. Customers that have not enabled…

  • CVE-2024-6198HigApr 25, 2025
    risk 0.50cvss epss 0.00

    The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker with access to the LAN…

  • CVE-2024-11917HigApr 25, 2025
    risk 0.53cvss 8.1epss 0.00

    The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_callback' functions. This…

  • CVE-2025-1565HigApr 25, 2025
    risk 0.49cvss 7.5epss 0.01

    The Mayosis Core plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.4.1 via the library/wave-audio/peaks/remote_dl.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server,…

  • CVE-2025-1279HigApr 25, 2025
    risk 0.57cvss 8.8epss 0.00

    The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ux_cb_tools_import_item_ajax AJAX action in all versions up to, and including, 3.16.2.1. This makes it…

  • CVE-2025-46617HigApr 25, 2025
    risk 0.47cvss 7.2epss 0.00

    Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configuration parameters via undocumented user credentials. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before…

  • CVE-2025-2238HigApr 25, 2025
    risk 0.57cvss 8.8epss 0.00

    The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to insufficient user_meta restrictions in the 'vikinger_user_meta_update_ajax' function. This makes it possible for authenticated attackers, with…

  • CVE-2025-46613HigApr 25, 2025
    risk 0.49cvss 7.5epss 0.00

    OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption because a thread may access handleConnections arguments after the parent stack frame becomes unavailable.

  • CVE-2025-3511HigApr 25, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link IE TSN FPGA module, CC-Link IE TSN Remote…

  • CVE-2025-43865HigApr 25, 2025
    risk 0.46cvss 8.2epss 0.01

    React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values ​​of the data object passed to the…

  • CVE-2025-43864HigApr 25, 2025
    risk 0.43cvss 7.5epss 0.20

    React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an application to switch to SPA mode by adding a header to the request. If the application uses SSR and is forced to switch to SPA, this causes an error that…

  • CVE-2025-3606HigApr 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Vestel AC Charger version 3.75.0 contains a vulnerability that could enable an attacker to access files containing sensitive information, such as credentials which could be used to further compromise the device.