VYPR
Vendor

GitHub

Products
267
CVEs
586
Across products
338
Status
Private

Products

267
View all 267 products →

Recent CVEs

586
View all 586 CVEs →
  • CVE-2018-15982HigKEVJan 18, 2019
    risk 0.78cvss 7.8epss 0.82

    Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2017-18365CriMar 28, 2019
    risk 0.68cvss 9.8epss 0.21

    The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute arbitrary code. This occurs because the enterprise session secret is always the same, and can be found in the product's source code.…

  • CVE-2017-17632CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.02

    Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.

  • CVE-2026-1728CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full…

  • CVE-2026-44887CriMay 27, 2026
    risk 0.64cvss 9.8epss 0.01

    Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitrary Python code to be injected into pialert.conf. Since the background scan daemon loads this file via Python's exec(), injected…

  • CVE-2026-8034CriMay 7, 2026
    risk 0.64cvss 9.8epss 0.00

    A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting URL parser confusion between the validation layer and the HTTP request library. The hostname…

  • CVE-2025-69902CriMar 16, 2026
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via injecting arbitrary shell metacharacters.

  • CVE-2026-31896CriMar 11, 2026
    risk 0.64cvss 9.8epss 0.00

    WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. The remover_produto_ocultar.php script uses extract($_REQUEST) to populate local variables and then directly concatenates these…

  • CVE-2026-28411CriFeb 27, 2026
    risk 0.64cvss 9.8epss 0.01

    WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal allows an unauthenticated attacker to overwrite local variables in multiple PHP scripts. This vulnerability can be leveraged to…

  • CVE-2026-0756CriJan 23, 2026
    risk 0.64cvss 9.8epss 0.02

    github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of github-kanban-mcp-server. Authentication is not required to exploit this vulnerability. …

  • CVE-2025-58745CriSep 8, 2025
    risk 0.64cvss 9.9epss 0.01

    WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. The WeGIA only check MIME types for Excel files at endpoint `/html/socio/sistema/controller/controla_xlsx.php`, which can be…

  • CVE-2025-53937CriJul 16, 2025
    risk 0.64cvss 9.8epss 0.00

    WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the `/controle/control.php` endpoint, specifically in the `cargo` parameter, of WeGIA prior to version 3.4.5. This…

  • CVE-2025-1861CriMar 30, 2025
    risk 0.64cvss 9.8epss 0.01

    In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024.…

  • CVE-2025-30365CriMar 27, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/html/socio/sistema/controller/query_geracao_auto.php, specifically in the query parameter. This vulnerability allows the execution…

  • CVE-2025-27782CriMar 19, 2025
    risk 0.64cvss 9.8epss 0.01

    Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in inference.py. This issue may lead to writing arbitrary files on the Applio server. It can also be used in conjunction with an unsafe deserialization to achieve remote…

  • CVE-2024-25825CriOct 9, 2024
    risk 0.64cvss 9.8epss 0.01

    FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password.

  • CVE-2024-6800CriAug 20, 2024
    risk 0.64cvss 9.8epss 0.02

    An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed signed federation metadata XML. This vulnerability allowed an attacker with direct network access to…

  • CVE-2024-4985CriMay 20, 2024
    risk 0.64cvss 9.8epss 0.03

    An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions feature. This vulnerability allowed an attacker to forge a SAML response to provision and/or gain…

  • CVE-2020-29297CriJan 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Multiple SQL Injection vulnerabilities in tourist5 Online-food-ordering-system 1.0.

  • CVE-2022-23739CriJan 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileges in GraphQL API requests from GitHub Apps. This vulnerability allowed an app installed on an organization to gain access to and modify most…