Latest CVE Feed
-
6.5
MEDIUMCVE-2025-36608
Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized... Read more
Affected Products : smartfabric_os10- Published: Jul. 30, 2025
- Modified: Aug. 06, 2025
- Vuln Type: XML External Entity
-
5.5
MEDIUMCVE-2025-30103
Dell SmartFabric OS10 Software, versions prior to 10.6.0.5 contains a Files or Directories Accessible to External Parties vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access... Read more
Affected Products : smartfabric_os10- Published: Jul. 30, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-5243
TP-Link Omada ER605 Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exploit thi... Read more
- Published: May. 23, 2024
- Modified: Aug. 06, 2025
-
7.8
HIGHCVE-2025-36609
Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.... Read more
Affected Products : smartfabric_os10- Published: Jul. 30, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authentication
-
5.0
MEDIUMCVE-2024-5244
TP-Link Omada ER605 Reliance on Security Through Obscurity Vulnerability. This vulnerability allows network-adjacent attackers to access or spoof DDNS messages on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exp... Read more
- Published: May. 23, 2024
- Modified: Aug. 06, 2025
-
8.8
HIGHCVE-2024-5291
D-Link DIR-2150 GetDeviceSettings Target Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Authentication is not requ... Read more
- Published: May. 23, 2024
- Modified: Aug. 06, 2025
-
8.8
HIGHCVE-2024-5293
D-Link DIR-2640 HTTP Referer Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2640-US routers. Authentication is not req... Read more
- Published: May. 23, 2024
- Modified: Aug. 06, 2025
-
6.5
MEDIUMCVE-2024-5294
D-Link DIR-3040 prog.cgi websSecurityHandler Memory Leak Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of D-Link DIR-3040 routers. Authentication is ... Read more
- Published: May. 23, 2024
- Modified: Aug. 06, 2025
-
9.8
CRITICALCVE-2024-5296
D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerabi... Read more
Affected Products : d-view_8- Published: May. 23, 2024
- Modified: Aug. 06, 2025
-
8.8
HIGHCVE-2024-5297
D-Link D-View executeWmicCmd Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View. Although authentication is required to exploit this vulner... Read more
Affected Products : d-view_8- Published: May. 23, 2024
- Modified: Aug. 06, 2025
-
8.8
HIGHCVE-2024-5298
D-Link D-View queryDeviceCustomMonitorResult Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View. Although authentication is required... Read more
Affected Products : d-view_8- Published: May. 23, 2024
- Modified: Aug. 06, 2025
-
8.8
HIGHCVE-2024-5299
D-Link D-View execMonitorScript Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View. Although authentication is required to exploit t... Read more
Affected Products : d-view_8- Published: May. 23, 2024
- Modified: Aug. 06, 2025
-
8.8
HIGHCVE-2023-27332
TP-Link Archer AX21 tdpServer Logging Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer AX21 routers. Authentication ... Read more
- Published: May. 03, 2024
- Modified: Aug. 06, 2025
-
6.8
MEDIUMCVE-2023-27333
TP-Link Archer AX21 tmpServer Command 0x422 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer AX21 routers. Authentic... Read more
- Published: May. 03, 2024
- Modified: Aug. 06, 2025
-
8.8
HIGHCVE-2023-27346
TP-Link AX1800 Firmware Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AX1800 routers. Authentication is not requ... Read more
- Published: May. 03, 2024
- Modified: Aug. 06, 2025
-
9.8
CRITICALCVE-2023-27359
TP-Link AX1800 hotplugd Firewall Rule Race Condition Vulnerability. This vulnerability allows remote attackers to gain access to LAN-side services on affected installations of TP-Link Archer AX21 routers. Authentication is not required to exploit this vul... Read more
- Published: May. 03, 2024
- Modified: Aug. 06, 2025
-
6.8
MEDIUMCVE-2023-32147
D-Link DIR-2640 LocalIPAddress Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2640 routers. Although authentication is required ... Read more
- Published: May. 03, 2024
- Modified: Aug. 06, 2025
-
6.5
MEDIUMCVE-2023-32148
D-Link DIR-2640 HNAP PrivateLogin Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-2640 routers. Authentication is not required to exploit this vulne... Read more
- Published: May. 03, 2024
- Modified: Aug. 06, 2025
-
9.8
CRITICALCVE-2024-2048
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certifica... Read more
Affected Products : vault- Published: Mar. 04, 2024
- Modified: Aug. 06, 2025
-
8.8
HIGHCVE-2023-32149
D-Link DIR-2640 prog.cgi Request Handling Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2640 routers. Authentication ... Read more
- Published: May. 03, 2024
- Modified: Aug. 06, 2025