VYPR

CVEs

115,701 total · page 791 of 2,315

  • CVE-2025-22222HigJan 30, 2025
    risk 0.50cvss 7.7epss 0.01

    VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.

  • CVE-2025-22218HigJan 30, 2025
    risk 0.55cvss 8.5epss 0.01

    VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs

  • CVE-2024-13720HigJan 30, 2025
    risk 0.57cvss 8.8epss 0.01

    The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the gky_image_uploader_main_function() function in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to…

  • CVE-2024-13707HigJan 30, 2025
    risk 0.57cvss 8.8epss 0.00

    The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the gky_image_uploader_main_function() function. This makes it possible for unauthenticated…

  • CVE-2024-13671HigJan 30, 2025
    risk 0.49cvss 7.5epss 0.01

    The Music Sheet Viewer plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.1 via the read_score_file() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can…

  • CVE-2024-13646HigJan 30, 2025
    risk 0.53cvss 8.1epss 0.00

    The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on the 'single_user_chat_update_login' function in all versions up to, and including, 0.5. This makes it possible for…

  • CVE-2024-12821HigJan 30, 2025
    risk 0.57cvss 8.8epss 0.00

    The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the upm_upload_media() function in all versions up to, and including, 3.12.0. This makes it possible…

  • CVE-2024-12269HigJan 30, 2025
    risk 0.49cvss 7.5epss 0.01

    The Safe Ai Malware Protection for WP plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_db() function in all versions up to, and including, 1.0.17. This makes it possible for unauthenticated attackers to retrieve a…

  • CVE-2024-12129HigJan 30, 2025
    risk 0.57cvss 8.8epss 0.00

    The Royal Core plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'royal_restore_backup' function in all versions up to, and including, 2.9.2. This makes it possible for…

  • CVE-2024-11600HigJan 30, 2025
    risk 0.40cvss 7.2epss 0.01

    The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.6.0 via the 'write_config' function. This is due to a lack of sanitization on an imported…

  • CVE-2024-10591HigJan 30, 2025
    risk 0.50cvss 8.8epss 0.00

    The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the hubwoo_save_updates()…

  • CVE-2025-0747HigJan 30, 2025
    risk 0.56cvss 8.6epss 0.00

    A Stored Cross-Site Scripting vulnerability has been found in EmbedAI. This vulnerability allows an authenticated attacker to inject a malicious JavaScript code into a message that will be executed when a user opens the chat.

  • CVE-2025-0745HigJan 30, 2025
    risk 0.49cvss 7.5epss 0.00

    An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain the backups of the database by requesting the "/embedai/app/uploads/database/<SQL_FILE>" endpoint.

  • CVE-2025-0744HigJan 30, 2025
    risk 0.49cvss 7.5epss 0.00

    an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker change his subscription plan without paying by making a POST request changing the parameters of the "/demos/embedai/pmt_cash_on_delivery/pay"…

  • CVE-2025-0740HigJan 30, 2025
    risk 0.56cvss 8.6epss 0.00

    An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain chat messages belonging to other users by changing the “CHAT_ID” of the endpoint "/embedai/chats/load_messages?chat_id=<CHAT_ID>".

  • CVE-2025-0739HigJan 30, 2025
    risk 0.56cvss 8.6epss 0.00

    An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to show subscription's information of others users by changing the "SUSCBRIPTION_ID" param of the endpoint "/demos/embedai/subscriptions/show/<SUS…

  • CVE-2024-13453HigJan 30, 2025
    risk 0.47cvss 7.3epss 0.01

    The The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.6.0. This is due to the software allowing users to execute an action that does not properly validate a…

  • CVE-2025-21107HigJan 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

  • CVE-2025-0834HigJan 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Privilege escalation vulnerability has been found in Wondershare Dr.Fone version 13.5.21. This vulnerability could allow an attacker to escalate privileges by replacing the binary ‘C:\ProgramData\Wondershare\wsServices\ElevationService.exe’ with a malicious binary. This…

  • CVE-2024-13694HigJan 30, 2025
    risk 0.42cvss 7.5epss 0.01

    The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.7 via the download_pdf_file() function due to missing validation on a…

  • CVE-2024-12708HigJan 30, 2025
    risk 0.46cvss 7.1epss 0.00

    The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting…

  • CVE-2024-12638HigJan 30, 2025
    risk 0.46cvss 7.1epss 0.01

    The Bulk Me Now! WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

  • CVE-2024-12400HigJan 30, 2025
    risk 0.46cvss 7.1epss 0.00

    The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

  • CVE-2025-23374HigJan 30, 2025
    risk 0.52cvss 8.0epss 0.00

    Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2025-0847HigJan 30, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can…

  • CVE-2025-0846HigJan 30, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/AdminLogin.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the…

  • CVE-2025-21396HigJan 29, 2025
    risk 0.53cvss 8.2epss 0.01

    Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-0843HigJan 29, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in needyamin Library Card System 1.0. It has been classified as critical. Affected is an unknown function of the file admindashboard.php of the component Admin Panel. The manipulation of the argument email/password leads to sql injection. It is possible…

  • CVE-2025-0842HigJan 29, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in needyamin Library Card System 1.0 and classified as critical. This issue affects some unknown processing of the file admin.php of the component Login. The manipulation of the argument email/password leads to sql injection. The attack may be initiated…

  • CVE-2024-57510HigJan 29, 2025
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial.

  • CVE-2024-57509HigJan 29, 2025
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_File::ParseStream and related functions.

  • CVE-2024-54851HigJan 29, 2025
    risk 0.57cvss 8.8epss 0.00

    Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection.

  • CVE-2024-48761HigJan 29, 2025
    risk 0.57cvss 8.8epss 0.01

    Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScript code via the "erro" parameter.

  • CVE-2024-23733HigJan 29, 2025
    risk 0.52cvss 7.5epss 0.02

    The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core_Fix7 allows remote attackers to reach the administration panel and discover hostname and version information by sending an arbitrary username and a blank…

  • CVE-2024-12705HigJan 29, 2025
    risk 0.50cvss 7.5epss 0.18

    Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through…

  • CVE-2024-11187HigJan 29, 2025
    risk 0.50cvss 7.5epss 0.15

    It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use…

  • CVE-2025-24793HigJan 29, 2025
    risk 0.39cvss 7.0epss 0.00

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the…

  • CVE-2025-0841HigJan 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability affects the function loadMore of the component News. The manipulation leads to deserialization. The attack can be initiated remotely. The exploit has been…

  • CVE-2024-10001HigJan 29, 2025
    risk 0.46cvss 7.1epss 0.00

    A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via the identity property in the message handling function. This enabled the exfiltration of sensitive data by manipulating the DOM,…

  • CVE-2025-24789HigJan 29, 2025
    risk 0.44cvss 7.8epss 0.00

    Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authentication method is used on Windows, an…

  • CVE-2025-24527HigJan 29, 2025
    risk 0.52cvss 8.0epss 0.00

    An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, they can execute debug commands on that connector.

  • CVE-2024-57436HigJan 29, 2025
    risk 0.47cvss 7.2epss 0.01

    RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a crafted cookie.

  • CVE-2024-54462HigJan 29, 2025
    risk 0.46cvss 7.1epss 0.00

    The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious document providers. This may result in cases where a user with a malicious document provider installed can select an image file from that provider while using your…

  • CVE-2024-54461HigJan 29, 2025
    risk 0.46cvss 7.1epss 0.00

    The file names constructed within file_selector are missing sanitization checks leaving them vulnerable to malicious document providers. This may result in cases where a user with a malicious document provider installed can select a document file from that provider while using…

  • CVE-2024-41140HigJan 29, 2025
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.

  • CVE-2025-0762HigJan 29, 2025
    risk 0.57cvss 8.8epss 0.00

    Use after free in DevTools in Google Chrome prior to 132.0.6834.159 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)

  • CVE-2021-3978HigJan 29, 2025
    risk 0.49cvss 7.5epss 0.00

    When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided service definition defaults to root ( https://github.com/cloudflare/cfrpki/blob/master/package/octorpki.service ) this could allow…

  • CVE-2024-7695HigJan 29, 2025
    risk 0.49cvss 7.5epss 0.01

    Multiple switches are affected by an out-of-bounds write vulnerability. This vulnerability is caused by insufficient input validation, which allows data to be written to memory outside the bounds of the buffer. Successful exploitation of this vulnerability could result in a…

  • CVE-2024-13696HigJan 29, 2025
    risk 0.40cvss 7.2epss 0.00

    The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wishlist_name’ parameter in all versions up to, and including, 1.2.25 due to insufficient input sanitization and output…

  • CVE-2024-12749HigJan 29, 2025
    risk 0.46cvss 7.1epss 0.01

    The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.