VYPR

CVEs

115,791 total · page 789 of 2,316

  • CVE-2025-20881HigFeb 4, 2025
    risk 0.46cvss 7.0epss 0.00

    Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

  • CVE-2024-10239HigFeb 4, 2025
    risk 0.47cvss 7.2epss 0.01

    A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6 . An attacker with administrator privileges can upload a specially crafted image, which can cause a stack overflow due to the unchecked fat->fsd.max_fld.

  • CVE-2024-10238HigFeb 4, 2025
    risk 0.47cvss 7.2epss 0.01

    A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6. An attacker can upload a specially crafted image that will cause a stack overflow is caused by not checking fld->used_bytes.

  • CVE-2024-10237HigFeb 4, 2025
    risk 0.47cvss 7.2epss 0.00

    There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker can modify the firmware to bypass BMC inspection and bypass the signature verification process

  • CVE-2024-13330HigFeb 4, 2025
    risk 0.46cvss 7.1epss 0.01

    The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2024-13329HigFeb 4, 2025
    risk 0.46cvss 7.1epss 0.00

    The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2025-1003HigFeb 4, 2025
    risk 0.55cvss epss 0.00

    A potential vulnerability has been identified in HP Anyware Agent for Linux which might allow for authentication bypass which may result in escalation of privilege. HP is releasing a software update to mitigate this potential vulnerability.

  • CVE-2025-24958HigFeb 3, 2025
    risk 0.57cvss 8.8epss 0.01

    WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `salvar_tag.php` endpoint. This vulnerability could allow an authorized attacker to execute arbitrary SQL queries, allowing access to or deletion of…

  • CVE-2025-24902HigFeb 3, 2025
    risk 0.00cvss 8.8epss 0.01

    WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `salvar_cargo.php` endpoint. This vulnerability could allow an authorized attacker to execute arbitrary SQL queries, allowing access to or deletion of…

  • CVE-2025-24901HigFeb 3, 2025
    risk 0.57cvss 8.8epss 0.01

    WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `deletar_permissao.php` endpoint. This vulnerability could allow an authorized attacker to execute arbitrary SQL queries, allowing access to or deletion of…

  • CVE-2025-24371HigFeb 3, 2025
    risk 0.39cvss epss 0.00

    CometBFT is a distributed, Byzantine fault-tolerant, deterministic state machine replication engine. In the `blocksync` protocol peers send their `base` and `latest` heights when they connect to a new node (`A`), which is syncing to the tip of a network. `base` acts as a lower…

  • CVE-2024-35177HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based environments. The wazuh-agent for Windows is vulnerable to a Local Privilege…

  • CVE-2025-24962HigFeb 3, 2025
    risk 0.00cvss 8.8epss 0.01

    reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nmap_cmd parameters. This issue has been addressed in commit `c28e5c8d` and is expected in the next versioned release. Users are advised to filter user…

  • CVE-2025-24960HigFeb 3, 2025
    risk 0.50cvss 8.7epss 0.01

    Jellystat is a free and open source Statistics App for Jellyfin. In affected versions Jellystat is directly using a user input in the route(s). This can lead to Path Traversal Vulnerabilities. Since this functionality is only for admin(s), there is very little scope for abuse.…

  • CVE-2025-24899HigFeb 3, 2025
    risk 0.00cvss 7.5epss 0.01

    reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where **an insider attacker with any role** (such as Auditor, Penetration Tester, or Sys Admin) **can extract sensitive information from other reNgine users.** After…

  • CVE-2025-22918HigFeb 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the use of administrator functions, resulting in the leakage of sensitive user information.

  • CVE-2024-57451HigFeb 3, 2025
    risk 0.49cvss 7.5epss 0.01

    ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which allows attackers to view any directory.

  • CVE-2024-56903HigFeb 3, 2025
    risk 0.53cvss 8.1epss 0.00

    Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against critical functionalities, such as account management. This vulnerability is used in chain with CVE-2024-56901 for a successful CSRF attack.

  • CVE-2024-56902HigFeb 3, 2025
    risk 0.54cvss 7.5epss 0.23

    Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.

  • CVE-2024-56901HigFeb 3, 2025
    risk 0.60cvss 8.8epss 0.02

    A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less that allows attackers to arbitrarily create Administrator accounts via a crafted GET request method. This vulnerability is used in chain with CVE-2024-56903 for a…

  • CVE-2024-56898HigFeb 3, 2025
    risk 0.60cvss 8.8epss 0.03

    Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, which can be leveraged to escalate privileges, create, modify or delete accounts.

  • CVE-2024-34897HigFeb 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.

  • CVE-2024-34896HigFeb 3, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected from a previous peer-to-peer connection with the device to still have access to live video feed.

  • CVE-2023-52163HigKEVFeb 3, 2025
    risk 0.77cvss 8.8epss 0.97

    Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2025-25064HigFeb 3, 2025
    risk 0.60cvss 8.8epss 0.37

    SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied parameter. Authenticated attackers can exploit this vulnerability by manipulating a…

  • CVE-2024-57669HigFeb 3, 2025
    risk 0.42cvss 7.5epss 0.01

    Directory Traversal vulnerability in Zrlog backup-sql-file.jar v.3.0.31 allows a remote attacker to obtain sensitive information via the BackupController.java file.

  • CVE-2024-57452HigFeb 3, 2025
    risk 0.49cvss 7.5epss 0.00

    ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows attackers to delete any file and folder.

  • CVE-2024-56921HigFeb 3, 2025
    risk 0.00cvss 7.5epss 0.00

    An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of gmm_state_exception() function upon receipt of the Nausf_UEAuthentication_Authenticate response.

  • CVE-2024-12859HigFeb 3, 2025
    risk 0.57cvss 8.8epss 0.01

    The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8.0 via the 'boombox_listing' shortcode 'type' attribute. This makes it possible for authenticated attackers, with contributor-level and above…

  • CVE-2024-12511HigFeb 3, 2025
    risk 0.49cvss 7.6epss 0.01

    With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.

  • CVE-2024-57238HigFeb 3, 2025
    risk 0.47cvss 7.3epss 0.00

    Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The vulnerability allows an attacker to manipulate SQL queries by injecting malicious SQL code into the order_by parameter.

  • CVE-2024-56161HigFeb 3, 2025
    risk 0.47cvss 7.2epss 0.01

    Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP.

  • CVE-2024-49843HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing IOCTL from user space to handle GPU AHB bus error.

  • CVE-2024-49840HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality.

  • CVE-2024-49839HigFeb 3, 2025
    risk 0.53cvss 8.2epss 0.00

    Memory corruption during management frame processing due to mismatch in T2LM info element.

  • CVE-2024-49838HigFeb 3, 2025
    risk 0.53cvss 8.2epss 0.00

    Information disclosure while parsing the OCI IE with invalid length.

  • CVE-2024-49837HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while reading CPU state data during guest VM suspend.

  • CVE-2024-49834HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while power-up or power-down sequence of the camera sensor.

  • CVE-2024-49833HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption can occur in the camera when an invalid CID is used.

  • CVE-2024-49832HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Camera due to unusually high number of nodes passed to AXI port.

  • CVE-2024-45584HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.

  • CVE-2024-45582HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while validating number of devices in Camera kernel .

  • CVE-2024-45573HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption may occour while generating test pattern due to negative indexing of display ID.

  • CVE-2024-45571HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface.

  • CVE-2024-45561HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while handling IOCTL call from user-space to set latency level.

  • CVE-2024-45560HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.

  • CVE-2024-38420HigFeb 3, 2025
    risk 0.57cvss 8.8epss 0.00

    Memory corruption while configuring a Hypervisor based input virtual device.

  • CVE-2024-38418HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while parsing the memory map info in IOCTL calls.

  • CVE-2024-38404HigFeb 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.

  • CVE-2025-24781HigFeb 3, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WPJobBoard allows Reflected XSS. This issue affects WPJobBoard: from n/a through 5.10.1.