Latest CVE Feed
-
7.5
HIGHCVE-2015-8314
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.... Read more
Affected Products : devise- Published: Dec. 12, 2023
- Modified: May. 27, 2025
-
8.1
HIGHCVE-2023-44857
An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 function in the acu_web component.... Read more
- Published: Apr. 12, 2024
- Modified: May. 27, 2025
-
7.8
HIGHCVE-2025-24274
An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. A malicious app may be able to gain root privileges.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-46631
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet access to the router's OS by sending a /goform/telnet web request.... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-46630
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a remote system management binary) by sending a /goform/ate web request.... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2023-44854
Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the c_set_rslog_decode function in the acu_web file.... Read more
- Published: Apr. 12, 2024
- Modified: May. 27, 2025
-
6.5
MEDIUMCVE-2025-46629
Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthorized configuration changes for any router where 'ate' has been enabled by sending a crafted UDP packet... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Authentication
-
7.3
HIGHCVE-2025-46628
Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain root shell access to the device by sending a crafted UDP packet to the 'ate' service when it is enabled. ... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2024-28339
An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.... Read more
- Published: Mar. 12, 2024
- Modified: May. 27, 2025
-
8.2
HIGHCVE-2025-46627
Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/oc... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-28340
An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.... Read more
- Published: Mar. 12, 2024
- Modified: May. 27, 2025
-
7.3
HIGHCVE-2025-46626
Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt, replay, and/or forge traffic to the service.... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Cryptography
-
8.8
HIGHCVE-2025-46625
Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web reque... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-3346
A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. Affected by this issue is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument pptp_server_start_ip/pptp_server_end_ip lead... Read more
- Published: Apr. 07, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-45514
Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.frmL7ImForm.... Read more
- Published: May. 07, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-44877
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- Published: May. 02, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-44872
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- Published: May. 02, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
8.4
HIGHCVE-2023-52070
JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of ... Read more
Affected Products : jfreechart- Published: Apr. 10, 2024
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2024-23077
JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the component /chart/plot/CompassPlot.java. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulne... Read more
Affected Products : jfreechart- Published: Apr. 10, 2024
- Modified: May. 27, 2025
-
9.1
CRITICALCVE-2024-22949
JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /chart/annotations/CategoryLineAnnotation. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a ... Read more
Affected Products : jfreechart- Published: Apr. 08, 2024
- Modified: May. 27, 2025