VYPR

CVEs

116,583 total · page 723 of 2,332

  • CVE-2025-32921HigApr 24, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpoperations Arrival arrival allows PHP Local File Inclusion.This issue affects Arrival: from n/a through <= 1.4.5.

  • CVE-2025-43855HigApr 24, 2025
    risk 0.50cvss epss 0.00

    tRPC allows users to build & consume fully typesafe APIs without schemas or code generation. In versions starting from 11.0.0 to before 11.1.1, an unhandled error is thrown when validating invalid connectionParams which crashes a tRPC WebSocket server. This allows any…

  • CVE-2025-27820HigApr 24, 2025
    risk 0.42cvss 7.5epss 0.01

    A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release

  • CVE-2025-3872HigApr 24, 2025
    risk 0.47cvss 7.2epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-web (User configuration form modules) allows SQL Injection. A user with high privileges is able to become administrator by intercepting the contact form…

  • CVE-2021-47663HigApr 24, 2025
    risk 0.53cvss 8.1epss 0.00

    Due to improper JSON Web Tokens implementation an unauthenticated remote attacker can guess a valid session ID and therefore impersonate a user to gain full access.

  • CVE-2021-47662HigApr 24, 2025
    risk 0.49cvss 7.5epss 0.00

    Due to missing authorization an unauthenticated remote attacker can cause a DoS attack by connecting via HTTPS and triggering the shutdown button.

  • CVE-2025-3776HigApr 24, 2025
    risk 0.54cvss 8.3epss 0.01

    The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions up to, and including, 1.5 via the 'targetvr_ajax_handler' function. This is due to a lack of validation on the type of function that can be called. This makes…

  • CVE-2025-3607HigApr 24, 2025
    risk 0.50cvss 8.8epss 0.00

    The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.8. This is due to the plugin not properly validating a user's identity prior to updating a password. This makes it…

  • CVE-2025-3300HigApr 24, 2025
    risk 0.47cvss 7.2epss 0.01

    The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to read and modify the contents…

  • CVE-2025-3101HigApr 24, 2025
    risk 0.57cvss 8.8epss 0.00

    The Configurator Theme Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.4.7. This is due to the plugin not properly validating user meta fields prior to updating them in the database. This makes it possible for authenticated…

  • CVE-2025-3058HigApr 24, 2025
    risk 0.57cvss 8.8epss 0.00

    The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the xwc_save_settings() function in all versions up to, and including, 9.1.0. This makes it possible for…

  • CVE-2025-1908HigApr 24, 2025
    risk 0.50cvss 7.7epss 0.00

    An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

  • CVE-2025-3761HigApr 24, 2025
    risk 0.50cvss 8.8epss 0.00

    The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.16. This is due to the mt_save_profile() function not appropriately restricting access to unauthorized users to update roles. This…

  • CVE-2025-2558HigApr 24, 2025
    risk 0.56cvss 8.6epss 0.02

    The-wound WordPress theme through 0.0.1 does not validate some parameters before using them to generate paths passed to include function/s, allowing unauthenticated users to perform LFI attacks and download arbitrary file from the server

  • CVE-2025-46417HigApr 24, 2025
    risk 0.42cvss 7.5epss 0.00

    The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deserialization.

  • CVE-2025-27580HigApr 24, 2025
    risk 0.49cvss 7.5epss 0.01

    NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, time, and the fixed 7Dl9#dj- string) and thus allows unauthenticated users with a Common Access Card (CAC) to escalate privileges and…

  • CVE-2025-46397HigApr 23, 2025
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.

  • CVE-2025-32818HigApr 23, 2025
    risk 0.49cvss 7.5epss 0.01

    A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition.

  • CVE-2025-28169HigApr 23, 2025
    risk 0.53cvss 8.1epss 0.00

    BYD QIN PLUS DM-i Dilink OS v3.0_13.1.7.2204050.1 to v3.0_13.1.7.2312290.1_0 was discovered to cend broadcasts to the manufacturer's cloud server unencrypted, allowing attackers to execute a man-in-the-middle attack.

  • CVE-2025-3904HigApr 23, 2025
    risk 0.47cvss 7.3epss 0.00

    Vulnerability in Drupal Sportsleague.This issue affects Sportsleague: *.*.

  • CVE-2025-3903HigApr 23, 2025
    risk 0.47cvss 7.3epss 0.00

    Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*.

  • CVE-2025-2773HigApr 23, 2025
    risk 0.47cvss 7.2epss 0.02

    BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BEC Technologies Multiple Routers. Although authentication is required to exploit…

  • CVE-2025-2769HigApr 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Bdrive NetDrive. An attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2025-2768HigApr 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Bdrive NetDrive. An attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2025-2765HigApr 23, 2025
    risk 0.57cvss 8.8epss 0.00

    CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of CarlinKit CPC200-CCPA devices. Authentication is not required to exploit…

  • CVE-2025-2764HigApr 23, 2025
    risk 0.52cvss 8.0epss 0.00

    CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of CarlinKit CPC200-CCPA devices. Although authentication is…

  • CVE-2025-2762HigApr 23, 2025
    risk 0.51cvss 7.8epss 0.00

    CarlinKit CPC200-CCPA Missing Root of Trust Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of CarlinKit CPC200-CCPA devices. An attacker must first obtain the ability to execute low-privileged…

  • CVE-2025-2761HigApr 23, 2025
    risk 0.51cvss 7.8epss 0.02

    GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2025-2760HigApr 23, 2025
    risk 0.51cvss 7.8epss 0.13

    GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2025-28028HigApr 23, 2025
    risk 0.47cvss 7.3epss 0.00

    TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi through the v5 parameter.

  • CVE-2025-28025HigApr 23, 2025
    risk 0.47cvss 7.3epss 0.00

    TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.

  • CVE-2025-28022HigApr 23, 2025
    risk 0.47cvss 7.3epss 0.00

    TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.

  • CVE-2025-28021HigApr 23, 2025
    risk 0.47cvss 7.3epss 0.00

    TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the downloadFile.cgi through the v14 and v3 parameters

  • CVE-2025-28020HigApr 23, 2025
    risk 0.47cvss 7.3epss 0.00

    TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.

  • CVE-2025-28019HigApr 23, 2025
    risk 0.47cvss 7.3epss 0.00

    TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi component

  • CVE-2025-28018HigApr 23, 2025
    risk 0.47cvss 7.3epss 0.00

    TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.

  • CVE-2025-1520HigApr 23, 2025
    risk 0.45cvss 8.0epss 0.00

    PostHog ClickHouse Table Functions SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PostHog. Authentication is required to exploit this vulnerability. The specific flaw…

  • CVE-2025-1050HigApr 23, 2025
    risk 0.57cvss 8.8epss 0.00

    Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. The specific flaw exists…

  • CVE-2025-1049HigApr 23, 2025
    risk 0.57cvss 8.8epss 0.00

    Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. The specific flaw…

  • CVE-2025-1048HigApr 23, 2025
    risk 0.57cvss 8.8epss 0.01

    Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. …

  • CVE-2025-1047HigApr 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Luxion KeyShot PVS File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in…

  • CVE-2025-1046HigApr 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Luxion KeyShot SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target…

  • CVE-2025-1045HigApr 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Luxion KeyShot Viewer KSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot Viewer. User interaction is required to exploit this…

  • CVE-2025-32968HigApr 23, 2025
    risk 0.57cvss 8.8epss 0.01

    XWiki is a generic wiki platform. In versions starting from 1.6-milestone-1 to before 15.10.16, 16.4.6, and 16.10.1, it is possible for a user with SCRIPT right to escape from the HQL execution context and perform a blind SQL injection to execute arbitrary SQL statements on the…

  • CVE-2025-21605HigApr 23, 2025
    risk 0.42cvss 7.5epss 0.01

    Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7.4.3, An unauthenticated client can cause unlimited growth of output buffers, until the server runs out of memory or is killed. By default, the Redis configuration does…

  • CVE-2025-42603HigApr 23, 2025
    risk 0.57cvss epss 0.00

    This vulnerability exists in the Meon KYC solutions due to transmission of sensitive data in plain text within the response payloads of certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting API response that contains unencrypted…

  • CVE-2025-42602HigApr 23, 2025
    risk 0.53cvss epss 0.00

    This vulnerability exists in Meon KYC solutions due to improper handling of access and refresh tokens in certain API endpoints of authentication process. A remote attacker could exploit this vulnerability by intercepting and manipulating the responses through API request body…

  • CVE-2025-42601HigApr 23, 2025
    risk 0.53cvss epss 0.00

    This vulnerability exists in Meon KYC solutions due to insufficient server-side validation of the Captcha in certain API endpoints. A remote attacker could exploit this vulnerability by intercepting the request and removing the Captcha parameter leading to bypassing the Captcha…

  • CVE-2025-42600HigApr 23, 2025
    risk 0.53cvss epss 0.00

    This vulnerability exists in Meon KYC solutions due to missing restrictions on the number of incorrect One-Time Password (OTP) attempts through certain API endpoints of login process. A remote attacker could exploit this vulnerability by performing a brute force attack on OTP,…

  • CVE-2025-3530HigApr 23, 2025
    risk 0.42cvss 7.5epss 0.01

    The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up to, and including, 5.1.2. This is due to a logic flaw involving the inconsistent use of parameters during the cart addition process. The plugin uses the…