VYPR

CVEs

115,870 total · page 777 of 2,318

  • CVE-2024-13888HigFeb 20, 2025
    risk 0.40cvss 7.2epss 0.01

    The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. This makes it possible for unauthenticated attackers to redirect…

  • CVE-2025-26856HigFeb 20, 2025
    risk 0.47cvss 7.2epss 0.01

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If an attacker logs in to the affected product with an administrative account and manipulates requests for a certain screen…

  • CVE-2025-1492HigFeb 20, 2025
    risk 0.51cvss 7.8epss 0.00

    Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file

  • CVE-2025-1293HigFeb 20, 2025
    risk 0.46cvss 8.2epss 0.00

    Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.

  • CVE-2024-12284HigFeb 20, 2025
    risk 0.58cvss 8.8epss 0.13

    Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.

  • CVE-2025-27092HigFeb 19, 2025
    risk 0.00cvss 7.5epss 0.01

    GHOSTS is an open source user simulation framework for cyber experimentation, simulation, training, and exercise. A path traversal vulnerability was discovered in GHOSTS version 8.0.0.0 that allows an attacker to access files outside of the intended directory through the photo…

  • CVE-2025-25944HigFeb 19, 2025
    risk 0.47cvss 7.3epss 0.00

    Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_RtpAtom::AP4_RtpAtom, during the execution of mp4fragment with a crafted MP4 input file.

  • CVE-2025-25943HigFeb 19, 2025
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component located in Ap4Stz2Atom.cpp.

  • CVE-2025-24989HigKEVFeb 19, 2025
    risk 0.65cvss 8.2epss 0.02

    An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been…

  • CVE-2025-21355HigFeb 19, 2025
    risk 0.56cvss 8.6epss 0.02

    Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network

  • CVE-2024-5706HigFeb 19, 2025
    risk 0.57cvss 8.8epss 0.01

    The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. (CWE-99)  Hitachi Vantara Pentaho Data Integration &…

  • CVE-2024-5705HigFeb 19, 2025
    risk 0.57cvss 8.8epss 0.00

    The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions. (CWE-863)     Hitachi Vantara Pentaho Business…

  • CVE-2024-37359HigFeb 19, 2025
    risk 0.56cvss 8.6epss 0.01

    The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. (CWE-918)   Hitachi Vantara Pentaho Business Analytics…

  • CVE-2023-51302HigFeb 19, 2025
    risk 0.57cvss 8.8epss 0.01

    PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to…

  • CVE-2023-51301HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail…

  • CVE-2025-0624HigFeb 19, 2025
    risk 0.50cvss 7.6epss 0.01

    A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During this step, it fails to consider the…

  • CVE-2023-51293HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail…

  • CVE-2023-46272HigFeb 19, 2025
    risk 0.57cvss 8.8epss 0.00

    Buffer Overflow vulnerability in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, allows an attacker to execute arbitrary code via the implementation of the ah_auth service

  • CVE-2025-0893HigFeb 19, 2025
    risk 0.51cvss 7.8epss 0.00

    Symantec Diagnostic Tool (SymDiag), prior to 3.0.79, may be susceptible to a Privilege Escalation vulnerability.

  • CVE-2020-10095HigFeb 19, 2025
    risk 0.53cvss 8.1epss 0.00

    Various Lexmark devices have CSRF that allows an attacker to modify the configuration of the device.

  • CVE-2025-24965HigFeb 19, 2025
    risk 0.48cvss epss 0.01

    crun is an open source OCI Container Runtime fully written in C. In affected versions A malicious container image could trick the krun handler into escaping the root filesystem, allowing file creation or modification on the host. No special permissions are needed, only the…

  • CVE-2025-1426HigFeb 19, 2025
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in GPU in Google Chrome on Android prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-1006HigFeb 19, 2025
    risk 0.57cvss 8.8epss 0.01

    Use after free in Network in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted web app. (Chromium security severity: Medium)

  • CVE-2025-0999HigFeb 19, 2025
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in V8 in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-52541HigFeb 19, 2025
    risk 0.53cvss 8.2epss 0.00

    Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

  • CVE-2023-47160HigFeb 19, 2025
    risk 0.53cvss 8.2epss 0.01

    IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

  • CVE-2024-45084HigFeb 19, 2025
    risk 0.52cvss 8.0epss 0.00

    IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents.

  • CVE-2024-28777HigFeb 19, 2025
    risk 0.57cvss 8.8epss 0.01

    IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allows users to execute arbitrary code, escalate privileges, or cause denial of service attacks by exploiting the unrestricted…

  • CVE-2024-52902HigFeb 19, 2025
    risk 0.57cvss 8.8epss 0.00

    IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system.

  • CVE-2025-1464HigFeb 19, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability, which was classified as critical, has been found in Baiyi Cloud Asset Management System up to 20250204. This issue affects some unknown processing of the file /wuser/admin.house.collect.php. The manipulation of the argument project_id leads to sql injection. The…

  • CVE-2025-0916HigFeb 19, 2025
    risk 0.47cvss 7.2epss 0.00

    The YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 2.4.9 to 2.6.2 due to insufficient input sanitization and output escaping. This makes it possible…

  • CVE-2024-13534HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.00

    The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 5.2.18 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2024-13533HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.01

    The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 1.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

  • CVE-2024-13491HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.00

    The Small Package Quotes – For Customers of FedEx plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 4.3.1 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2024-13485HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.01

    The LTL Freight Quotes – ABF Freight Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2024-13483HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.01

    The LTL Freight Quotes – SAIA Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 2.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2024-13481HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.01

    The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2024-13479HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.01

    The LTL Freight Quotes – SEFL Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 3.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2024-13478HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.01

    The LTL Freight Quotes – TForce Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2025-1075HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.00

    Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p27, <2.2.0p40, and 2.1.0p51 (EOL) causes LDAP credentials to be written to Apache error log file accessible to administrators.

  • CVE-2024-13489HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.01

    The LTL Freight Quotes – Old Dominion Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 4.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2025-1135HigFeb 19, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in ChurchCRM 5.13.0. and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL Injection vulnerability in the BatchWinnerEntry functionality. The CurrentFundraiser parameter is directly…

  • CVE-2025-1134HigFeb 19, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL Injection vulnerability in the DonatedItemEditor functionality. The CurrentFundraiser parameter is directly…

  • CVE-2025-1133HigFeb 19, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL Injection vulnerability in the EditEventAttendees functionality. The EID parameter is directly concatenated into an SQL query…

  • CVE-2025-1132HigFeb 19, 2025
    risk 0.57cvss 8.8epss 0.01

    A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. The parameter is directly inserted into an SQL query without proper sanitization, allowing attackers to inject malicious SQL commands.…

  • CVE-2024-13592HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.01

    The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0 via the 'team-builder-vc' shortcode. This makes it possible for authenticated attackers, with…

  • CVE-2024-13468HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.01

    The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'duplicates-action-top' action in all versions up to, and including, 1.9. This makes it possible for unauthenticated attackers to delete…

  • CVE-2024-11582HigFeb 19, 2025
    risk 0.47cvss 7.2epss 0.00

    The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ip parameter in all versions up to, and including, 10.43 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2025-1448HigFeb 19, 2025
    risk 0.48cvss 7.3epss 0.03

    A vulnerability was found in Synway SMG Gateway Management Software up to 20250204. It has been rated as critical. This issue affects some unknown processing of the file 9-12ping.php. The manipulation of the argument retry leads to command injection. The attack may be initiated…

  • CVE-2024-57262HigFeb 19, 2025
    risk 0.39cvss 7.1epss 0.00

    In barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite, a related issue to CVE-2024-57256.