VYPR

Manager

by Manager Io

Source repositories

CVEs (10)

  • CVE-2025-64180CriNov 7, 2025
    risk 0.65cvss 10.0epss 0.00

    Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vulnerability permits unauthorized access to internal network resources. The flaw lies in the fundamental design of the DNS validation mechanism. A Time-of-Check…

  • CVE-2024-52034CriNov 22, 2024
    risk 0.65cvss 10.0epss 0.02

    An OS Command Injection vulnerability exists within myPRO Manager. A parameter within a command can be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.

  • CVE-2020-8592CriFeb 3, 2020
    risk 0.64cvss 9.8epss 0.01

    eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password feature).

  • CVE-2020-8591CriFeb 3, 2020
    risk 0.64cvss 9.8epss 0.01

    eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.

  • CVE-2025-54122CriJul 21, 2025
    risk 0.58cvss 10.0epss 0.01

    Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulnerability has been identified in the proxy handler component of both manager Desktop and Server edition versions up to and including 25.7.18.2519. This…

  • CVE-2010-1603Apr 29, 2010
    risk 0.04cvss epss 0.07

    Directory traversal vulnerability in the ZiMB Core (aka ZiMBCore or com_zimbcore) component 0.1 in the ZiMB Manager collection for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to…

  • CVE-2008-7167Sep 8, 2009
    risk 0.03cvss epss 0.04

    Unrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

  • CVE-2025-61583MedOct 1, 2025
    risk 0.00cvss 4.3epss 0.00

    TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability has been identified in versions 2.2.1 and earlier. The vulnerability exists in the error handling mechanism of the login page, where malicious scripts embedded…

  • CVE-2025-61582HigOct 1, 2025
    risk 0.00cvss 7.5epss 0.00

    TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A Denial of Dervice vulnerability has been identified in versions 2.2.1 and earlier. The vulnerability permits an unauthenticated actor to crash the application through the submission of specially crafted…

  • CVE-2007-5291Oct 9, 2007
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Edit.asp in DB Manager 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.