Latest CVE Feed
-
5.7
MEDIUMCVE-2024-51004
Netgear R8500 v1.0.2.160 and R7000P v1.3.3.154 were discovered to multiple stack overflow vulnerabilities in the component usb_device.cgi via the cifs_user, read_access, and write_access parameters. These vulnerabilities allow attackers to cause a Denial ... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 30, 2025
-
5.7
MEDIUMCVE-2024-51001
Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the sysDNSHost parameter at ddns.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 22, 2025
-
5.7
MEDIUMCVE-2024-51022
Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the ssid parameter in bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Nov. 05, 2024
- Modified: May. 02, 2025
-
5.7
MEDIUMCVE-2024-50998
Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component openvpn.cgi via the openvpn_service_port and openvpn_service_port_tun parameters. These vulnerabilities allow attackers to cause a Denial of Servic... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 22, 2025
-
5.7
MEDIUMCVE-2024-50995
Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 22, 2025
-
5.7
MEDIUMCVE-2024-51000
Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component wireless.cgi via the opmode, opmode_an, and opmode_an_2 parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a ... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 22, 2025
-
5.7
MEDIUMCVE-2020-13344
An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are stored in plain-text in Redis which allows attacker with Redis access to authenticate as any user that has a session stored in Redis... Read more
Affected Products : gitlab- Published: Oct. 08, 2020
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2019-11251
The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combination of two symlinks provided by tar output of a malicious container to place a file outside of the destination directory specified i... Read more
Affected Products : kubernetes- Published: Feb. 03, 2020
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2024-4859
Solidus <= 4.3.4 is affected by a Stored Cross-Site Scripting vulnerability in the order tracking URL. ... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-29432
Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.... Read more
Affected Products : sydent- Published: Apr. 15, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2016-2116
Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file.... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
5.7
MEDIUMCVE-2021-25011
The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's se... Read more
Affected Products : wp_google_map- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-24968
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Sub... Read more
Affected Products : ultimate_faq- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-24752
Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPre... Read more
- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-24703
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.... Read more
Affected Products : download_plugin- Published: Nov. 23, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2025-50157
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Information Disclosure
-
5.7
MEDIUMCVE-2018-1000161
nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a vict... Read more
Affected Products : nmap- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2025-1001
Medixant RadiAnt DICOM Viewer is vulnerable due to failure of the update mechanism to verify the update server's certificate which could allow an attacker to alter network traffic and carry out a machine-in-the-middle attack (MITM). An attacker could modi... Read more
Affected Products :- Published: Feb. 21, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Misconfiguration
-
5.7
MEDIUMCVE-2018-0414
A vulnerability in the web-based UI of Cisco Secure Access Control Server could allow an authenticated, remote attacker to gain read access to certain information in an affected system. The vulnerability is due to improper handling of XML External Entitie... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2017-9546
admin.php in BigTree through 4.2.18 allows remote authenticated users to cause a denial of service (inability to save revisions) via XSS sequences in a revision name.... Read more
Affected Products : bigtree_cms- Published: Jun. 12, 2017
- Modified: Apr. 20, 2025