VYPR
Vendor

Vulncheck

Products
10
CVEs
10
Across products
10
Status
Private

Products

10

Recent CVEs

10
  • CVE-2025-34160CriAug 27, 2025
    risk 0.65cvss —epss 0.01

    AnyShare contains a critical unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port 10250. The endpoint /api/ServiceAgent/start_service accepts user-supplied input via POST and fails to sanitize command-like payloads. An attacker can inject…

  • CVE-2023-54399CriSep 18, 2026
    risk 0.64cvss 9.8epss 0.00

    Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped. An unauthenticated remote attacker can supply a crafted…

  • CVE-2010-20115CriAug 21, 2025
    risk 0.64cvss —epss 0.01

    Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a memory corruption vulnerability triggered by a malformed FTP PORT command. The flaw arises from an out-of-bounds array access during input parsing, allowing an attacker to manipulate…

  • CVE-2025-34128HigJul 16, 2025
    risk 0.59cvss —epss 0.01

    A buffer overflow vulnerability exists in the X360 VideoPlayer ActiveX control (VideoPlayer.ocx) version 2.6 when handling overly long arguments to the ConvertFile() method. An attacker can exploit this vulnerability by supplying crafted input to cause memory corruption and…

  • CVE-2016-20046HigMar 28, 2026
    risk 0.55cvss 8.4epss 0.00

    zFTP Client 20061220+dfsg3-4.1 contains a buffer overflow vulnerability in the NAME parameter handling of FTP connections that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized NAME value exceeding the 80-byte buffer…

  • CVE-2020-37013HigJan 29, 2026
    risk 0.55cvss 8.4epss 0.00

    Audio Playback Recorder 3.2.2 contains a local buffer overflow vulnerability in the eject and registration parameters that allows attackers to execute arbitrary code. Attackers can craft malicious payloads and overwrite Structured Exception Handler (SEH) to execute shellcode…

  • CVE-2019-25612HigMar 22, 2026
    risk 0.51cvss 7.8epss 0.00

    Admin Express 1.2.5.485 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an alphanumeric encoded payload in the Folder Path field. Attackers can trigger the vulnerability through the…

  • CVE-2021-47838HigJan 16, 2026
    risk 0.47cvss 7.2epss 0.00

    Markright 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to embed malicious payloads in markdown files. Attackers can upload specially crafted markdown files that execute arbitrary JavaScript when opened, potentially enabling remote code…

  • CVE-2025-34502HigOct 24, 2025
    risk 0.46cvss —epss 0.00

    Deck Mate 2 lacks a verified secure-boot chain and runtime integrity validation for its controller and display modules. Without cryptographic boot verification, an attacker with physical access can modify or replace the bootloader, kernel, or filesystem and gain persistent code…

  • CVE-2026-70622MedAug 10, 2026
    risk 0.35cvss 6.5epss 0.00

    tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-controlled directory. When a privileged…