Latest CVE Feed
-
7.2
HIGHCVE-2024-21682
This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira... Read more
Affected Products : assets_discovery_data_center- Published: Feb. 20, 2024
- Modified: Apr. 30, 2025
-
6.4
MEDIUMCVE-2025-3458
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ocean_gallery_id’ parameter in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authe... Read more
Affected Products : ocean_extra- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-3472
The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shor... Read more
Affected Products : ocean_extra- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-25431
Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_data parameter on the /captive_portal.htm page.... Read more
- Published: Feb. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-29743
D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.... Read more
- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45427
In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead to remote arbitrary code execution.... Read more
- Published: Apr. 23, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3341
A vulnerability, which was classified as critical, was found in codeprojects Online Restaurant Management System 1.0. This affects an unknown part of the file /admin/reservation_view.php. The manipulation of the argument ID leads to sql injection. It is p... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3342
A vulnerability has been found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/payment_save.php. The manipulation of the argument ID leads to sql injection. The... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3343
A vulnerability was found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/reservation_update.php. The manipulation of the argument ID leads to sql injection.... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3344
A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/assign_save.php. The manipulation of the argument ID leads to sql injection. It is po... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3345
A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/combo.php. The manipulation of the argument del leads to sql... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-29087
In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer... Read more
Affected Products : sqlite- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2024-27570
LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the generate_conf_router function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
Affected Products : lbt-t300_firmware lbt-t300 lbt-t390_firmware lbt-t390 lbt-t300-t390_firmware lbt-t300-t390- Published: Mar. 01, 2024
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2024-27572
LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the updateCurAPlist function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Mar. 01, 2024
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2024-27571
LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the makeCurRemoteApList function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Mar. 01, 2024
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2024-27569
LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the init_nvram function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Mar. 01, 2024
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2024-27568
LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the apn_name_3g parameter in the setupEC20Apn function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Mar. 01, 2024
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2024-27567
LBT T300- T390 v2.2.1.8 were discovered to contain a stack overflow via the vpn_client_ip parameter in the config_vpn_pptp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Mar. 01, 2024
- Modified: Apr. 30, 2025
-
7.1
HIGHCVE-2020-27792
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead t... Read more
- EPSS Score: %0.03
- Published: Aug. 19, 2022
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2025-0395
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page siz... Read more
Affected Products : glibc- Published: Jan. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Memory Corruption