VYPR

Vendor CVEs

Github.com

All CVEs

23 total · sorted by risk
  • CVE-2021-28411CriAug 11, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi version 3.4.0, allows remote attackers to escalate privileges.

  • CVE-2018-19185CriNov 12, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c. This is exploitable even after CVE-2018-18834 has been patched, with a different dataSetValue sequence than the CVE-2018-18834 attack vector.

  • CVE-2024-47775CriDec 12, 2024
    risk 0.59cvss 9.1epss 0.01

    GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been found in the parse_ds64 function within gstwavparse.c. The parse_ds64 function does not check that the buffer buf contains sufficient data before attempting to read…

  • CVE-2023-33480HigNov 7, 2023
    risk 0.57cvss 8.8epss 0.02

    RemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials to create admin users, escalate privileges, and execute arbitrary code on the target system via a PHP shell. The vulnerabilities are caused by…

  • CVE-2024-27528HigNov 8, 2024
    risk 0.55cvss 8.4epss 0.00

    wasm3 139076a suffers from Invalid Memory Read, leading to DoS and potential Code Execution.

  • CVE-2025-45237HigMay 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.

  • CVE-2021-43313HigMar 24, 2023
    risk 0.49cvss 7.5epss 0.01

    A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in the function PackLinuxElf32::invert_pt_dynamic at p_lx_elf.cpp:1688.

  • CVE-2026-50138higJul 1, 2026
    risk 0.45cvss epss

    # WebDAV listener ignores `--read-only`, `--upload-only`, and `--no-delete` mode flags **Ecosystem:** Go **Package:** `goshs.de/goshs/v2` (`github.com/patrickhener/goshs`) **Affected:** `<= v2.0.9` (every release that ships the WebDAV handler) ## Summary When `goshs` is…

  • CVE-2020-18416MedJun 27, 2023
    risk 0.44cvss 6.8epss 0.00

    An cross site request forgery (CSRF) vulnerability discovered in Jymusic v2.0.0.,that allows attackers to execute arbitrary code via /admin.php?s=/addons/config.html&id=6 to modify payment information.

  • CVE-2026-24670MedFeb 3, 2026
    risk 0.42cvss 6.5epss 0.00

    The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulnerability allows authenticated students to create new course units, an action normally restricted to higher-privileged roles. This…

  • CVE-2023-47417MedNov 20, 2023
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in the component /shells/embedder.html of DZSlides after v2011.07.25 allows attackers to execute arbitrary code via a crafted payload.

  • CVE-2019-5310MedJan 4, 2019
    risk 0.40cvss 6.1epss 0.01

    YUNUCMS 1.1.8 has XSS in app/admin/controller/System.php because crafted data can be written to the sys.php file, as demonstrated by site_title in an admin/system/basic POST request.

  • CVE-2020-18770MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in function zzip_disk_entry_to_file_header in mmapped.c in zziplib 0.13.69, which will lead to a denial-of-service.

  • CVE-2021-46516MedJan 27, 2022
    risk 0.36cvss 5.5epss 0.01

    Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_stack_size at mjs/src/mjs_core.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2021-39541MedSep 20, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function Analyze::AnalyzeXref() located in analyze.cpp. It allows an attacker to cause Denial of Service.

  • CVE-2022-44952MedDec 2, 2022
    risk 0.35cvss 5.4epss 0.01

    Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Copyright Text…

  • CVE-2015-10020MedJan 14, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability has been found in ssn2013 cis450Project and classified as critical. This vulnerability affects the function addUser of the file HeatMapServer/src/com/datformers/servlet/AddAppUser.java. The manipulation leads to sql injection. The name of the patch is…

  • CVE-2026-34441MedMar 31, 2026
    risk 0.24cvss 4.8epss 0.00

    cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.40.0, cpp-httplib is vulnerable to HTTP Request Smuggling. The server's static file handler serves GET responses without consuming the request body. On HTTP/1.1 keep-alive…

  • CVE-2026-10173MedMay 31, 2026
    risk 0.21cvss 4.3epss 0.00

    A weakness has been identified in Orthanc Explorer 2 up to 1.12.0. The impacted element is an unknown function of the file WebApplication/src/components/StudyList.vue of the component URL Handler. This manipulation of the argument remote-source causes cross site scripting. It is…

  • CVE-2025-5166LowMay 26, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function MDCImporter::InternReadFile of the file assimp/code/AssetLib/MDC/MDCLoader.cpp of the component MDC File Parser. The manipulation of the argument…

  • CVE-2026-17552CriJul 27, 2026
    risk 0.00cvss 9.1epss 0.00

    Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call. When the rewrite base is a plain string, the REQUEST_URI is appended to it, with no check that the path starts with a forward slash ('/'). …

  • CVE-2025-66577MedDec 5, 2025
    risk 0.00cvss 5.3epss 0.00

    cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP headers to influence server-visible metadata, logging, and authorization decisions. An attacker can supply X-Forwarded-For or…

  • CVE-2022-30767CriMay 16, 2022
    risk 0.00cvss 9.8epss 0.03

    nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.