VYPR

CVEs

116,471 total · page 739 of 2,330

  • CVE-2025-26639HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-26628HigApr 8, 2025
    risk 0.48cvss 7.3epss 0.01

    Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally.

  • CVE-2025-24074HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24073HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24062HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24060HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24058HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-21222HigApr 8, 2025
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

  • CVE-2025-21221HigApr 8, 2025
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

  • CVE-2025-21205HigApr 8, 2025
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

  • CVE-2025-21204HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.07

    Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

  • CVE-2025-21191HigApr 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-21174HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

  • CVE-2025-32117HigApr 8, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Reflected XSS.This issue affects Widgetize Pages Light: from n/a through <= 3.0.

  • CVE-2025-27083HigApr 8, 2025
    risk 0.47cvss 7.2epss 0.01

    Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker to execute arbitrary commands as a privileged user on…

  • CVE-2025-27082HigApr 8, 2025
    risk 0.47cvss 7.2epss 0.01

    Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary…

  • CVE-2025-25227HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.00

    Insufficient state checks lead to a vector that allows to bypass 2FA checks.

  • CVE-2025-3289HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the…

  • CVE-2025-3288HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose…

  • CVE-2025-3287HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the…

  • CVE-2025-3286HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose…

  • CVE-2025-3285HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose…

  • CVE-2025-32018HigApr 8, 2025
    risk 0.52cvss 8.0epss 0.00

    Cursor is a code editor built for programming with AI. In versions 0.45.0 through 0.48.6, the Cursor app introduced a regression affecting the set of file paths the Cursor Agent is permitted to modify automatically. Under specific conditions, the agent could be prompted, either…

  • CVE-2025-32017HigApr 8, 2025
    risk 0.50cvss 8.8epss 0.01

    Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is…

  • CVE-2025-2829HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose…

  • CVE-2025-2293HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose…

  • CVE-2025-2288HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose…

  • CVE-2025-2287HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To…

  • CVE-2025-2286HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To…

  • CVE-2025-2285HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To…

  • CVE-2025-1095HigApr 8, 2025
    risk 0.57cvss 8.8epss 0.00

    IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM.…

  • CVE-2025-32406HigApr 8, 2025
    risk 0.56cvss 8.6epss 0.01

    An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows remote attackers fetch and parse the XML response.

  • CVE-2025-22466HigApr 8, 2025
    risk 0.53cvss 8.2epss 0.01

    Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.

  • CVE-2025-22461HigApr 8, 2025
    risk 0.47cvss 7.2epss 0.01

    SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privileges to achieve code execution.

  • CVE-2025-22458HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.

  • CVE-2025-31498HigApr 8, 2025
    risk 0.47cvss epss 0.01

    c-ares is an asynchronous resolver library. From 1.32.3 through 1.34.4, there is a use-after-free in read_answers() when process_answer() may re-enqueue a query either due to a DNS Cookie Failure or when the upstream server does not properly support EDNS, or possibly on TCP…

  • CVE-2025-30151HigApr 8, 2025
    risk 0.42cvss 7.5epss 0.00

    Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also…

  • CVE-2025-25254HigApr 8, 2025
    risk 0.47cvss 7.2epss 0.15

    An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, 7.2 all versions, 7.0 all versions endpoint may allow an authenticated admin to access and modify the filesystem…

  • CVE-2024-54024HigApr 8, 2025
    risk 0.47cvss 7.2epss 0.01

    An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator before version 2.4.6 allows a privileged attacker with super-admin profile and CLI access to execute unauthorized code via specifically…

  • CVE-2024-26013HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.00

    A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2,…

  • CVE-2023-37930HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.01

    Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.

  • CVE-2025-29986HigApr 8, 2025
    risk 0.54cvss 8.3epss 0.00

    Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Common Anti-Virus Agent (CAVA). An unauthenticated attacker with remote access could potentially exploit this vulnerability,…

  • CVE-2025-2807HigApr 8, 2025
    risk 0.50cvss 8.8epss 0.01

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it…

  • CVE-2025-3064HigApr 8, 2025
    risk 0.50cvss 8.8epss 0.00

    The WPFront User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.1. This is due to missing or incorrect nonce validation on the whitelist_options() function. This makes it possible for unauthenticated…

  • CVE-2025-22015HigApr 8, 2025
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: mm/migrate: fix shmem xarray update during migration A shmem folio can be either in page cache or in swap cache, but not at the same time. Namely, once it is in swap cache, folio->mapping should be NULL, and…

  • CVE-2025-22013HigApr 8, 2025
    risk 0.47cvss 7.3epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Unconditionally save+flush host FPSIMD/SVE/SME state There are several problems with the way hyp code lazily saves the host's FPSIMD/SVE state, including: * Host SVE being discarded unexpectedly…

  • CVE-2025-22012HigApr 8, 2025
    risk 0.57cvss 8.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: Revert "arm64: dts: qcom: sdm845: Affirm IDR0.CCTW on apps_smmu" There are reports that the pagetable walker cache coherency is not a given across the spectrum of SDM845/850 devices, leading to lock-ups and…

  • CVE-2024-41793HigApr 8, 2025
    risk 0.56cvss 8.6epss 0.01

    A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices provides an endpoint that allows to enable the ssh service without authentication. This could allow an unauthenticated remote attacker to enable remote…

  • CVE-2024-41792HigApr 8, 2025
    risk 0.56cvss 8.6epss 0.01

    A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices contains a path traversal vulnerability. This could allow an unauthenticated attacker it to access arbitrary files on the device with root privileges.

  • CVE-2024-41791HigApr 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not authenticate report creation requests. This could allow an unauthenticated remote attacker to read or clear the log files on the device, reset…