Latest CVE Feed
-
4.7
MEDIUMCVE-2021-27853
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.... Read more
Affected Products : ios_xe sg500-28mpp_firmware sg500-52mp_firmware sf500-24_firmware sf500-24p_firmware sf500-48_firmware sg500-28_firmware sg500-28p_firmware sg500-52_firmware sg500-52p_firmware +299 more products- EPSS Score: %0.03
- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2025-1104
A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown code. The manipulation leads to authentication bypass by spoofing. The attack can be initiated remotely. The exploit has been disclosed... Read more
- Published: Feb. 07, 2025
- Modified: May. 21, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-55532
Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes this issue.... Read more
Affected Products : ranger- Published: Mar. 03, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
5.7
MEDIUMCVE-2024-56914
D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp.... Read more
- Published: Jan. 22, 2025
- Modified: May. 21, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-25429
Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the r_name variable inside the have_same_name function on the /addschedule.htm page.... Read more
- Published: Feb. 28, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
8.0
HIGHCVE-2025-25428
TRENDnet TEW-929DRU 1.0.0.10 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.... Read more
- Published: Feb. 28, 2025
- Modified: May. 21, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-25430
Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the configname parameter on the /cbi_addcert.htm page.... Read more
- Published: Feb. 28, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
8.6
HIGHCVE-2024-13726
The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection... Read more
Affected Products : themes_coder- Published: Feb. 17, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2024-37607
A Buffer overflow vulnerability in D-Link DAP-2555 REVA_FIRMWARE_1.20 allows remote attackers to cause a Denial of Service (DoS) via a crafted HTTP request.... Read more
- Published: Dec. 17, 2024
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2024-37606
A Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.... Read more
- Published: Dec. 17, 2024
- Modified: May. 21, 2025
-
7.3
HIGHCVE-2024-42093
In the Linux kernel, the following vulnerability has been resolved: net/dpaa2: Avoid explicit cpumask var allocation on stack For CONFIG_CPUMASK_OFFSTACK=y kernel, explicit allocation of cpumask variable on stack is not recommended since it can cause po... Read more
Affected Products : linux_kernel- Published: Jul. 29, 2024
- Modified: May. 21, 2025
-
7.0
HIGHCVE-2024-41057
In the Linux kernel, the following vulnerability has been resolved: cachefiles: fix slab-use-after-free in cachefiles_withdraw_cookie() We got the following issue in our fault injection stress test: =====================================================... Read more
Affected Products : linux_kernel- Published: Jul. 29, 2024
- Modified: May. 21, 2025
-
6.0
MEDIUMCVE-2024-56662
In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl Fix an issue detected by syzbot with KASAN: BUG: KASAN: vmalloc-out-of-bounds in cmd_to_func drivers/acpi/nfit/ core.c:416 [inli... Read more
Affected Products : linux_kernel- Published: Dec. 27, 2024
- Modified: May. 21, 2025
-
7.1
HIGHCVE-2024-50705
Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary scripts via the page parameter.... Read more
Affected Products : tripleplay- Published: Mar. 04, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-1955
A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Scheduling/scheduling/pages/profile.php. The manipulation of the ar... Read more
- Published: Mar. 04, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-48246
Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /vehicle-management/booking.php.... Read more
- Published: Mar. 05, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-37605
A NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.... Read more
- Published: Dec. 17, 2024
- Modified: May. 21, 2025
-
6.1
MEDIUMCVE-2024-13868
The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against hig... Read more
Affected Products : url_shortener_\|_conversion_tracking_\|_ab_testing_\|_woocommerce- Published: Mar. 06, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2024-36831
A NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02_HOTFIX allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request without authentication.... Read more
- Published: Dec. 17, 2024
- Modified: May. 21, 2025
-
7.6
HIGHCVE-2025-0624
A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During this step, it fails... Read more
Affected Products : enterprise_linux openshift_container_platform grub2 international_components_for_unicode- Published: Feb. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Memory Corruption