Latest CVE Feed
-
5.7
MEDIUMCVE-2024-52016
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component wlg_adv.cgi via the apmode_dns1_pri and apmode_dns1_sec parameters. These vulnerabilities allo... Read more
Affected Products : r7000p_firmware r6400v2_firmware xr300_firmware r8500_firmware r7000p r8500 xr300 r6400v2- Published: Nov. 05, 2024
- Modified: May. 21, 2025
-
5.7
MEDIUMCVE-2025-25209
The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those secretes are already in the kuadrant-system instead of copying it to the referred namespace. This creates space for a malicious actor w... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Information Disclosure
-
5.7
MEDIUMCVE-2024-3130
Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm and key obtained after decompiling app ... Read more
Affected Products :- Published: Apr. 01, 2024
- Modified: Aug. 27, 2025
-
5.7
MEDIUMCVE-2024-26311
Archer Platform 6.x before 6.14 P2 HF1 (6.14.0.2.1) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this by tricking a victim application user into supplying malicious JavaScript code to the v... Read more
Affected Products : archer- Published: Feb. 21, 2024
- Modified: Mar. 18, 2025
-
5.7
MEDIUMCVE-2024-55582
Oxide before 6 has unencrypted Control Plane datastores.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 11, 2024
-
5.7
MEDIUMCVE-2025-25208
A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Denial of Service
-
5.7
MEDIUMCVE-2025-25207
The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authorino allows the users with developer persona to add callbacks to be executed to HTTP endpoints once the authorization process is complete... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Denial of Service
-
5.7
MEDIUMCVE-2025-53719
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Information Disclosure
-
5.7
MEDIUMCVE-2025-8997
An Information Exposure vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited.... Read more
Affected Products :- Published: Aug. 25, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Information Disclosure
-
5.7
MEDIUMCVE-2022-3881
The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.43 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as... Read more
Affected Products : wptools- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
5.7
MEDIUMCVE-2025-54624
Unexpected injection event vulnerability in the multimodalinput module. Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Aug. 06, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Injection
-
5.7
MEDIUMCVE-2025-53153
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Information Disclosure
-
5.7
MEDIUMCVE-2025-4437
There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specifying a non-existent user, CRI-O attempts to create the user, reading the container's entire /etc/passwd file into memory. If this file i... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Denial of Service
-
5.7
MEDIUMCVE-2025-4084
Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Oth... Read more
- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Misconfiguration
-
5.7
MEDIUMCVE-2025-48002
Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent network.... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Information Disclosure
-
5.7
MEDIUMCVE-2025-46805
Screen version 5.0.0 and older version 4 releases have a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to privileged processes when installed setuid-root.... Read more
Affected Products :- Published: May. 26, 2025
- Modified: May. 28, 2025
- Vuln Type: Race Condition
-
5.7
MEDIUMCVE-2025-46741
A suspended or recently logged-out user could continue to interact with Blueframe until the time-out period occurred.... Read more
Affected Products :- Published: May. 12, 2025
- Modified: May. 12, 2025
- Vuln Type: Authentication
-
5.7
MEDIUMCVE-2024-58257
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Injection
-
5.7
MEDIUMCVE-2025-43485
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could potentially allow a privileged user to retrieve credentials from the log files. HP has addressed the issue in the lat... Read more
Affected Products : poly_clariti_manager_firmware- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure
-
5.7
MEDIUMCVE-2025-43486
A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website allows user input to be stored and rendered without proper sanitization. HP has addressed the issue in the lat... Read more
Affected Products : poly_clariti_manager_firmware- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting