VYPR

CVEs

115,979 total · page 768 of 2,320

  • CVE-2025-23465HigMar 3, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magent Vampire Character Manager vampire-character allows Reflected XSS.This issue affects Vampire Character Manager: from n/a through <= 2.13.

  • CVE-2025-23464HigMar 3, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Keir Whitaker Twitter News Feed twitter-news-feed allows Reflected XSS.This issue affects Twitter News Feed: from n/a through <= 1.1.1.

  • CVE-2025-23451HigMar 3, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in titodevera Awesome Twitter Feeds awesome-twitter-feeds allows Reflected XSS.This issue affects Awesome Twitter Feeds: from n/a through <= 1.0.

  • CVE-2025-23450HigMar 3, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in agenwebsite AW WooCommerce Kode Pembayaran aw-woocommerce-kode-pembayaran allows Reflected XSS.This issue affects AW WooCommerce Kode Pembayaran: from n/a through <= 1.1.4.

  • CVE-2025-23447HigMar 3, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kundan Yevale Smooth Dynamic Slider smooth-dynamic-slider allows Reflected XSS.This issue affects Smooth Dynamic Slider: from n/a through <= 1.0.

  • CVE-2025-23446HigMar 3, 2025
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in KokoenDE WP SpaceContent wp-spacecontent allows Stored XSS.This issue affects WP SpaceContent: from n/a through <= 0.4.5.

  • CVE-2025-23441HigMar 3, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dkukral Attach Gallery Posts attach-gallery-posts allows Reflected XSS.This issue affects Attach Gallery Posts: from n/a through <= 1.6.

  • CVE-2025-23439HigMar 3, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in willshouse TinyMCE Extended Config tinymce-extended-config allows Reflected XSS.This issue affects TinyMCE Extended Config: from n/a through <= 0.1.0.

  • CVE-2025-23437HigMar 3, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nord_tramper ntp-header-images header-images-rotator allows Reflected XSS.This issue affects ntp-header-images: from n/a through <= 1.2.

  • CVE-2025-23433HigMar 3, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jnwry vcOS vcos allows Reflected XSS.This issue affects vcOS: from n/a through <= 1.4.0.

  • CVE-2025-23425HigMar 3, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in marekki Marekkis Watermark marekkis-watermark allows Reflected XSS.This issue affects Marekkis Watermark: from n/a through <= 0.9.4.

  • CVE-2025-21424HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while calling the NPU driver APIs concurrently.

  • CVE-2025-0475HigMar 3, 2025
    risk 0.57cvss 8.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.

  • CVE-2024-53034HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed with the DriverKnownEscape flag reset.

  • CVE-2024-53033HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer address.

  • CVE-2024-53032HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption may occur in keyboard virtual device due to guest VM interaction.

  • CVE-2024-53031HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.

  • CVE-2024-53030HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing input message passed from FE driver.

  • CVE-2024-53029HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.

  • CVE-2024-53028HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption may occur while processing message from frontend during allocation.

  • CVE-2024-53027HigMar 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS may occur while processing the country IE.

  • CVE-2024-53024HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in display driver while detaching a device.

  • CVE-2024-53023HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption may occur while accessing a variable during extended back to back tests.

  • CVE-2024-53022HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption may occur during communication between primary and guest VM.

  • CVE-2024-53014HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption may occur while validating ports and channels in Audio driver.

  • CVE-2024-53012HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption may occur due to improper input validation in clock device.

  • CVE-2024-53011HigMar 3, 2025
    risk 0.51cvss 7.9epss 0.00

    Information disclosure may occur due to improper permission and access controls to Video Analytics engine.

  • CVE-2024-49836HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption may occur during the synchronization of the camera`s frame processing pipeline.

  • CVE-2024-45580HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.

  • CVE-2024-43062HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization.

  • CVE-2024-43061HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.

  • CVE-2024-43060HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.

  • CVE-2024-43059HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.

  • CVE-2024-43057HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing command in Glink linux.

  • CVE-2024-43055HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing camera use case IOCTL call.

  • CVE-2025-24846HigMar 3, 2025
    risk 0.49cvss 7.5epss 0.01

    Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may obtain the device information such as MAC address by sending a specially crafted…

  • CVE-2025-24654HigMar 3, 2025
    risk 0.46cvss 7.1epss 0.00

    Missing Authorization vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo.This issue affects SEO Plugin by Squirrly SEO: from n/a through <= 12.4.07.

  • CVE-2025-1859HigMar 3, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability, which was classified as critical, has been found in PHPGurukul News Portal 4.1. This issue affects some unknown processing of the file /login.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has…

  • CVE-2025-1858HigMar 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in Codezips Online Shopping Website 1.0. This vulnerability affects unknown code of the file /success.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2025-1857HigMar 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file /check_availability.php. The manipulation of the argument employeeid leads to sql injection. It is possible to initiate the…

  • CVE-2025-1856HigMar 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Codezips Gym Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /dashboard/admin/gen_invoice.php. The manipulation of the argument id leads to sql injection. The attack may be…

  • CVE-2025-1723HigMar 3, 2025
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.

  • CVE-2025-1853HigMar 3, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda AC8 16.03.34.06 and classified as critical. This issue affects the function sub_49E098 of the file /goform/SetIpMacBind of the component Parameter Handler. The manipulation of the argument list leads to stack-based buffer overflow. The attack…

  • CVE-2025-1852HigMar 3, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical. This vulnerability affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to buffer overflow. The attack can be…

  • CVE-2025-1851HigMar 3, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, was found in Tenda AC7 up to 15.03.06.44. This affects the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The manipulation of the argument firewallEn leads to stack-based buffer overflow. It is possible to…

  • CVE-2025-1850HigMar 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Codezips College Management System 1.0. Affected by this issue is some unknown functionality of the file /university.php. The manipulation of the argument book_name leads to sql injection. The attack may be…

  • CVE-2025-20645HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09475476; Issue…

  • CVE-2025-25951HigMar 3, 2025
    risk 0.49cvss 7.5epss 0.00

    An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information.

  • CVE-2025-25950HigMar 3, 2025
    risk 0.53cvss 8.1epss 0.00

    Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.

  • CVE-2025-1841HigMar 3, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical has been found in ESAFENET CDG 5.6.3.154.205. This affects an unknown part of the file /CDGServer3/logManagement/ClientSortLog.jsp. The manipulation of the argument startDate/endDate leads to sql injection. It is possible to initiate the…