Latest CVE Feed
-
8.2
HIGHCVE-2022-29181
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or r... Read more
- Published: May. 20, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-26112
In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default fro... Read more
Affected Products : pinot- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
8.8
HIGHCVE-2021-3187
An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can elevate privileges by running a malicious script (that executes as root from a temporary directory) during install time. (This applies ... Read more
- Published: Dec. 11, 2023
- Modified: May. 27, 2025
-
8.1
HIGHCVE-2020-36604
hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function.... Read more
Affected Products : hoek- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2018-16153
An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some situations.... Read more
Affected Products : opencast- Published: Dec. 12, 2023
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2015-8314
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.... Read more
Affected Products : devise- Published: Dec. 12, 2023
- Modified: May. 27, 2025
-
8.1
HIGHCVE-2023-44857
An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 function in the acu_web component.... Read more
- Published: Apr. 12, 2024
- Modified: May. 27, 2025
-
7.8
HIGHCVE-2025-24274
An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. A malicious app may be able to gain root privileges.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-46631
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet access to the router's OS by sending a /goform/telnet web request.... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-46630
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a remote system management binary) by sending a /goform/ate web request.... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2023-44854
Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the c_set_rslog_decode function in the acu_web file.... Read more
- Published: Apr. 12, 2024
- Modified: May. 27, 2025
-
6.5
MEDIUMCVE-2025-46629
Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthorized configuration changes for any router where 'ate' has been enabled by sending a crafted UDP packet... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Authentication
-
7.3
HIGHCVE-2025-46628
Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain root shell access to the device by sending a crafted UDP packet to the 'ate' service when it is enabled. ... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2024-28339
An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.... Read more
- Published: Mar. 12, 2024
- Modified: May. 27, 2025
-
8.2
HIGHCVE-2025-46627
Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/oc... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-28340
An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.... Read more
- Published: Mar. 12, 2024
- Modified: May. 27, 2025
-
7.3
HIGHCVE-2025-46626
Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt, replay, and/or forge traffic to the service.... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Cryptography
-
8.8
HIGHCVE-2025-46625
Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web reque... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-3346
A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. Affected by this issue is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument pptp_server_start_ip/pptp_server_end_ip lead... Read more
- Published: Apr. 07, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-45514
Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.frmL7ImForm.... Read more
- Published: May. 07, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption