Latest CVE Feed
-
6.1
MEDIUMCVE-2022-32166
In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modifi... Read more
- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
4.3
MEDIUMCVE-2022-2760
In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an error message when a resource is part of another Space.... Read more
Affected Products : octopus_server- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
5.3
MEDIUMCVE-2022-23716
A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster.... Read more
Affected Products : elastic_cloud_enterprise- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
7.8
HIGH- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
3.7
LOWCVE-2021-43980
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18... Read more
- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2021-41433
SQL Injection vulnerability exists in version 1.0 of the Resumes Management and Job Application Website application login form by EGavilan Media that allows authentication bypass through login.php.... Read more
Affected Products : resumes_management_and_job_application_website_application- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
4.7
MEDIUMCVE-2021-27862
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length and Ethernet to Wifi frame conversion (and optionally VLAN0 headers).... Read more
- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
4.7
MEDIUMCVE-2021-27861
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length (and optionally VLAN0 headers)... Read more
- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
4.7
MEDIUMCVE-2021-27854
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations of VLAN 0 headers, LLC/SNAP headers, and converting frames from Ethernet to Wifi and its reverse.... Read more
- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
4.6
MEDIUMCVE-2025-26091
A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter whe... Read more
Affected Products : team_password_manager- Published: Mar. 04, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-33072
Improper access control in Azure allows an unauthorized attacker to disclose information over a network.... Read more
- Published: May. 08, 2025
- Modified: May. 21, 2025
- Vuln Type: Authorization
-
5.7
MEDIUMCVE-2024-44674
D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.... Read more
- Published: Oct. 07, 2024
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2025-47732
Microsoft Dataverse Remote Code Execution Vulnerability... Read more
Affected Products : dataverse- Published: May. 08, 2025
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2024-44589
Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows attackers to execute of arbitrary code.... Read more
- Published: Sep. 18, 2024
- Modified: May. 21, 2025
-
9.1
CRITICALCVE-2025-47733
Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network... Read more
Affected Products : power_apps- Published: May. 08, 2025
- Modified: May. 21, 2025
- Vuln Type: Server-Side Request Forgery
-
6.5
MEDIUMCVE-2024-33774
A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."... Read more
- Published: May. 14, 2024
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2024-33773
A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanGuestSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."... Read more
- Published: May. 14, 2024
- Modified: May. 21, 2025
-
5.7
MEDIUMCVE-2024-33772
A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formTcpipSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "curTime."... Read more
- Published: May. 14, 2024
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2024-33771
A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via goform/formWPS, allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."... Read more
- Published: May. 14, 2024
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2025-4773
A vulnerability was found in PHPGurukul Online Course Registration 3.1 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/level.php. The manipulation of the argument level leads to sql injection. The attack... Read more
Affected Products : online_course_registration- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection