Latest CVE Feed
-
5.5
MEDIUMCVE-2024-44915
An issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).... Read more
- Published: Aug. 28, 2024
- Modified: May. 23, 2025
-
5.5
MEDIUMCVE-2024-44913
An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).... Read more
- Published: Aug. 28, 2024
- Modified: May. 23, 2025
-
7.8
HIGHCVE-2021-36340
Dell EMC SCG 5.00.00.10 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulnerability to read sensitive information and use it.... Read more
- Published: Nov. 20, 2021
- Modified: May. 23, 2025
-
9.8
CRITICALCVE-2025-4788
A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unknown functionality of the component DELETE Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotel... Read more
- Published: May. 16, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4789
A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is some unknown functionality of the component LCD Command Handler. The manipulation leads to buffer overflow. The attack may be launched... Read more
- Published: May. 16, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4790
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part of the component GLOB Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The ex... Read more
- Published: May. 16, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4791
A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. This vulnerability affects unknown code of the component HASH Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The expl... Read more
- Published: May. 16, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-4782
A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /sms/admin/?page=receiving/view_receiving&id=1. The manipulation of the argument ID lead... Read more
Affected Products : stock_management_system- Published: May. 16, 2025
- Modified: May. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-47688
Missing Authorization vulnerability in Saad Iqbal Advanced File Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced File Manager: from n/a through 5.3.1.... Read more
Affected Products : advanced_file_manager- Published: May. 07, 2025
- Modified: May. 23, 2025
- Vuln Type: Authorization
-
9.0
HIGHCVE-2025-4462
A vulnerability, which was classified as critical, has been found in TOTOLINK N150RT 3.4.0-B20190525. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of the argument localPin leads to buffer overflow. The attack ma... Read more
- Published: May. 09, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-4461
A vulnerability classified as problematic was found in TOTOLINK N150RT 3.4.0-B20190525. This vulnerability affects unknown code of the component Virtual Server Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The... Read more
- Published: May. 09, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-4460
A vulnerability classified as problematic has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the component URL Filtering Page. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. ... Read more
- Published: May. 09, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-47612
Missing Authorization vulnerability in flowdee ClickWhale allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ClickWhale: from n/a through 2.4.6.... Read more
Affected Products : clickwhale- Published: May. 07, 2025
- Modified: May. 23, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-51547
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.... Read more
- Published: Feb. 06, 2025
- Modified: May. 23, 2025
- Vuln Type: Authentication
-
8.7
HIGHCVE-2025-4008
The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is ... Read more
Affected Products :- Published: May. 21, 2025
- Modified: May. 23, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2015-7848
An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode packet. The crafted packet needs to have the correct message authentication code and a valid timestamp. When... Read more
- Published: Jan. 06, 2017
- Modified: May. 23, 2025
-
9.8
CRITICALCVE-2024-36761
naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.... Read more
- Published: Jun. 12, 2024
- Modified: May. 23, 2025
-
9.8
CRITICALCVE-2022-40864
Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setSmartPowerManagement with the request /goform/PowerSaveSet... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
9.8
CRITICALCVE-2022-40862
Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with the request /goform/NatStaticSetting... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
9.8
CRITICALCVE-2022-40860
Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBand->FUN_0007dd20 with request /goform/SetNetControlList... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025