VYPR
Vendor

EMule X Ray

Products
36
CVEs
37
Across products
35
Status
Private

Products

36
View all 36 products →

Recent CVEs

37
View all 37 CVEs →
  • CVE-2019-1000023CriFeb 4, 2019
    risk 0.64cvss 9.8epss 0.02

    OPT/NET BV OPTOSS Next Gen Network Management System (NG-NetMS) version v3.6-2 and earlier versions contains a SQL Injection vulnerability in Identified vulnerable parameters: id, id_access_type and id_attr_access that can result in a malicious attacker can include own SQL…

  • CVE-2016-8863CriMar 7, 2017
    risk 0.64cvss 9.8epss 0.08

    Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the…

  • CVE-2012-10056HigAug 13, 2025
    risk 0.60cvss epss 0.01

    PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnerability in its document upload functionality. Authenticated users can upload files to the mods/documents/uploads/ directory without any restriction on file type or extension. Because this directory is…

  • CVE-2018-25417HigMay 30, 2026
    risk 0.53cvss 8.2epss 0.00

    AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the quality parameter. Attackers can send GET requests to quality.php with crafted SQL payloads in the quality…

  • CVE-2018-25414HigMay 30, 2026
    risk 0.53cvss 8.2epss 0.00

    AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the actor parameter. Attackers can send GET requests to actor.php with crafted SQL payloads in the actor…

  • CVE-2018-25413HigMay 30, 2026
    risk 0.53cvss 8.2epss 0.00

    AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'q' parameter. Attackers can send GET requests to search.php with crafted SQL payloads to extract sensitive…

  • CVE-2020-15395HigJun 30, 2020
    risk 0.51cvss 7.8epss 0.01

    In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fill_PerStream in Multiple/File_MpegPs.cpp (aka an off-by-one during MpegPs parsing).

  • CVE-2020-37088HigFeb 3, 2026
    risk 0.49cvss 7.5epss 0.03

    School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to…

  • CVE-2023-48161HigNov 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the DumpSCreen2RGB function in gif2rgb.c

  • CVE-2017-11722MedJul 28, 2017
    risk 0.42cvss 6.5epss 0.02

    The WriteOnePNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file, because the program's actual control flow was inconsistent with its indentation. This…

  • CVE-2024-34749MedMay 14, 2024
    risk 0.40cvss 6.1epss 0.01

    Phormer prior to version 3.35 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote unauthenticated attacker may execute an arbitrary script on the web browser of the user.

  • CVE-2019-8938MedMar 21, 2019
    risk 0.40cvss 6.1epss 0.02

    VertrigoServ 2.17 allows XSS via the /inc/extensions.php ext parameter.

  • CVE-2023-46316MedOct 25, 2023
    risk 0.36cvss 5.5epss 0.00

    In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines.

  • CVE-2012-1614Sep 4, 2012
    risk 0.04cvss epss 0.09

    Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page or (3) cat parameter to thumbnails.php, an invalid (4) page parameter to usermgr.php, or an invalid…

  • CVE-2011-5185Sep 20, 2012
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in video_comments.php in Online Subtitles Workshop before 2.0 rev 131 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.

  • CVE-2008-3714Aug 19, 2008
    risk 0.03cvss epss 0.06

    Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.

  • CVE-2008-2298May 18, 2008
    risk 0.03cvss epss 0.03

    Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1.

  • CVE-2008-0501Jan 30, 2008
    risk 0.03cvss epss 0.02

    Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page_courante parameter to the top-level URI.

  • CVE-2007-1572Mar 21, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter, a different vector than CVE-2007-1440. NOTE: the provenance of this information is unknown; the details are obtained…

  • CVE-2002-2362Dec 31, 2002
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the noticemsg parameter.