VYPR

CVEs

115,831 total · page 781 of 2,317

  • CVE-2025-26549HigFeb 13, 2025
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in pa1 WP Html Page Sitemap wp-html-page-sitemap allows Stored XSS.This issue affects WP Html Page Sitemap: from n/a through <= 2.2.

  • CVE-2025-26547HigFeb 13, 2025
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in nagarjunsonti My Login Logout Plugin my-loginlogout allows Stored XSS.This issue affects My Login Logout Plugin: from n/a through <= 2.4.

  • CVE-2025-26545HigFeb 13, 2025
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in shisuh Related Posts Line-up-Exactly by Milliard related-posts-line-up-exactry-by-milliard allows Stored XSS.This issue affects Related Posts Line-up-Exactly by Milliard: from n/a through <= 0.0.22.

  • CVE-2025-26543HigFeb 13, 2025
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Pukhraj Suthar Simple Responsive Menu simple-responsive-menu allows Stored XSS.This issue affects Simple Responsive Menu: from n/a through <= 2.1.

  • CVE-2025-1247HigFeb 13, 2025
    risk 0.47cvss 8.3epss 0.01

    A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.

  • CVE-2025-1094HigFeb 13, 2025
    risk 0.63cvss 8.1epss 0.90

    Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires…

  • CVE-2025-21700HigFeb 13, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: net: sched: Disallow replacing of child qdisc from one parent to another Lion Ackermann was able to create a UAF which can be abused for privilege escalation with the following script Step 1. create root…

  • CVE-2024-13606HigFeb 13, 2025
    risk 0.49cvss 7.5epss 0.00

    The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'jssupportticketdata' directory. This makes it possible for unauthenticated attackers to extract…

  • CVE-2024-46910HigFeb 13, 2025
    risk 0.39cvss 7.1epss 0.01

    An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are recommended to upgrade to version 2.4.0, which fixes the issue.

  • CVE-2025-0327HigFeb 13, 2025
    risk 0.51cvss 7.8epss 0.00

    CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when an…

  • CVE-2024-13346HigFeb 13, 2025
    risk 0.48cvss 7.3epss 0.02

    The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value…

  • CVE-2024-13345HigFeb 13, 2025
    risk 0.47cvss 7.3epss 0.01

    The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it…

  • CVE-2025-1070HigFeb 13, 2025
    risk 0.53cvss 8.1epss 0.00

    CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could render the device inoperable when a malicious file is downloaded.

  • CVE-2025-1060HigFeb 13, 2025
    risk 0.49cvss 7.5epss 0.00

    CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network traffic is being sniffed by an attacker.

  • CVE-2025-1059HigFeb 13, 2025
    risk 0.49cvss 7.5epss 0.00

    CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause communications to stop when malicious packets are sent to the webserver of the device.

  • CVE-2025-1058HigFeb 13, 2025
    risk 0.53cvss 8.1epss 0.00

    CWE-494: Download of Code Without Integrity Check vulnerability exists that could render the device inoperable when malicious firmware is downloaded.

  • CVE-2024-13770HigFeb 13, 2025
    risk 0.53cvss 8.1epss 0.01

    The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2.4 via deserialization of untrusted input 'view_more_posts' AJAX action. This makes it possible for…

  • CVE-2024-51376HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.01

    Directory Traversal vulnerability in yeqifu carRental v.1.0 allows a remote attacker to obtain sensitive information via the file/downloadFile.action?path= component.

  • CVE-2024-34520HigFeb 12, 2025
    risk 0.57cvss 8.8epss 0.00

    An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an authenticated 'guest' user to perform unauthorized administrative actions, such as accessing the 'add user' feature, by bypassing…

  • CVE-2024-56940HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) via excessive file uploads.

  • CVE-2024-51440HigFeb 12, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component.

  • CVE-2024-51123HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in Zertificon Z1 SecureMail Z1 SecureMail Gateway 4.44.2-7240-debian12 allows a remote attacker to obtain sensitive information via the /compose-pdf.xhtml?convid=[id] component.

  • CVE-2024-46923HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. The absence of a null check leads to a Denial of Service at amdgpu_cs_ib_fill in the Xclipse Driver.

  • CVE-2024-46922HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The absence of a null check leads to a Denial of Service at amdgpu_cs_parser_bos in the Xclipse Driver.

  • CVE-2024-41917HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.00

    Time-of-check time-of-use race condition for some Intel(R) Battery Life Diagnostic Tool software before version 2.4.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-41168HigFeb 12, 2025
    risk 0.48cvss 7.4epss 0.00

    Use after free in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2024-39805HigFeb 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Insufficient verification of data authenticity in some Intel(R) DSA software before version 23.4.39 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-39356HigFeb 12, 2025
    risk 0.48cvss 7.4epss 0.00

    NULL pointer dereference in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2024-38310HigFeb 12, 2025
    risk 0.53cvss 8.2epss 0.00

    Improper access control in some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-38307HigFeb 12, 2025
    risk 0.50cvss 7.7epss 0.01

    Improper input validation in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow an authenticated user to potentially enable denial of service via network access.

  • CVE-2024-37355HigFeb 12, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper access control in some Intel(R) Graphics software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-36262HigFeb 12, 2025
    risk 0.47cvss 7.2epss 0.00

    Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-32941HigFeb 12, 2025
    risk 0.51cvss 7.9epss 0.00

    NULL pointer dereference for some Intel(R) MLC software before version v3.11b may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2024-31858HigFeb 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds write for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-31155HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-29214HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-28127HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-24582HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-49618HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-49615HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper input validation in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-49603HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.00

    Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-48267HigFeb 12, 2025
    risk 0.51cvss 7.9epss 0.00

    Improper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-43758HigFeb 12, 2025
    risk 0.53cvss 8.2epss 0.00

    Improper input validation in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-34440HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-31276HigFeb 12, 2025
    risk 0.53cvss 8.2epss 0.00

    Heap-based buffer overflow in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R) Server Board S2600BP, before version 02.01.0017 and Intel(R) Server Board M50CYP and Intel(R) Server Board D50TNP before version R01.01.0009 may allow a…

  • CVE-2023-29164HigFeb 12, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper access control in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R) Server Board S2600BP, before version 02.01.0017 and Intel(R) Server Board M50CYP and Intel(R) Server Board D50TNP before version R01.01.0009 may allow an…

  • CVE-2025-0110HigFeb 12, 2025
    risk 0.56cvss epss 0.01

    A command injection vulnerability in the Palo Alto Networks PAN-OS OpenConfig plugin enables an authenticated administrator with the ability to make gNMI requests to the PAN-OS management web interface to bypass system restrictions and run arbitrary commands. The commands are…

  • CVE-2024-12673HigFeb 12, 2025
    risk 0.51cvss 7.8epss 0.00

    An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges on the system. This vulnerability only affects Vantage installed on these devices: * Lenovo V…

  • CVE-2025-25283HigFeb 12, 2025
    risk 0.42cvss 7.5epss 0.01

    parse-duraton is software that allows users to convert a human readable duration to milliseconds. Versions prior to 2.1.3 are vulnerable to an event loop delay due to the CPU-bound operation of resolving the provided string, from a 0.5ms and up to ~50ms per one operation, with a…

  • CVE-2025-25205HigFeb 12, 2025
    risk 0.00cvss 8.2epss 0.05

    Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic allows unauthenticated requests to match certain unanchored regex patterns in the URL. Attackers can craft URLs…