Latest CVE Feed
-
6.8
MEDIUMCVE-2023-32150
D-Link DIR-2640 PrefixLen Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2640 routers. Although authentication is required to ex... Read more
- Published: May. 03, 2024
- Modified: Aug. 06, 2025
-
6.8
MEDIUMCVE-2023-32151
D-Link DIR-2640 DestNetwork Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2640 routers. Although authentication is required to ... Read more
- Published: May. 03, 2024
- Modified: Aug. 06, 2025
-
6.5
MEDIUMCVE-2023-32152
D-Link DIR-2640 HNAP LoginPassword Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-2640 routers. Authentication is not required to exploit this vuln... Read more
- Published: May. 03, 2024
- Modified: Aug. 06, 2025
-
6.8
MEDIUMCVE-2023-32153
D-Link DIR-2640 EmailFrom Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2640 routers. Although authentication is required to ex... Read more
- Published: May. 03, 2024
- Modified: Aug. 06, 2025
-
3.3
LOWCVE-2023-51612
Kofax Power PDF JP2 File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power PDF. User interaction is required to exploit this v... Read more
- Published: May. 03, 2024
- Modified: Aug. 06, 2025
-
6.9
MEDIUMCVE-2013-10062
A directory traversal vulnerability exists in Linksys router's web interface (tested on the E1500 model firmware versions 1.0.00, 1.0.04, and 1.0.05), specifically in the /apply.cgi endpoint. Authenticated attackers can exploit the next_page POST paramete... Read more
Affected Products :- Published: Aug. 01, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Path Traversal
-
8.6
HIGHCVE-2013-10058
An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) running firmware version v2.0.03 via the apply.cgi endpoint. The web interface fails to properly sanitize user-supplied input passed to the p... Read more
Affected Products :- Published: Aug. 01, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2013-10047
An unrestricted file upload vulnerability exists in MiniWeb HTTP Server <= Build 300 that allows unauthenticated remote attackers to upload arbitrary files to the server’s filesystem. By abusing the upload handler and crafting a traversal path, an attacke... Read more
Affected Products :- Published: Aug. 01, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authentication
-
9.3
CRITICALCVE-2012-10027
WP-Property plugin for WordPress through version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a temporary directory without authentication, lead... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authentication
-
8.5
HIGHCVE-2012-10022
Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege escalation from uid 48. The lxsuexec binary performs a uid check and permits execution of arbitrary commands as root if the invoking user ... Read more
Affected Products :- Published: Aug. 01, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2023-35748
D-Link DAP-2622 DDP Firmware Upgrade Server IPv6 Address Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. ... Read more
- Published: May. 07, 2024
- Modified: Aug. 06, 2025
-
8.8
HIGHCVE-2023-35749
D-Link DAP-2622 DDP Firmware Upgrade Filename Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authenticat... Read more
- Published: May. 07, 2024
- Modified: Aug. 06, 2025
-
5.4
MEDIUMCVE-2023-37325
D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to make unauthorized changes to device configuration on affected installations of D-Link DAP-2622 routers. Authentication is not r... Read more
- Published: May. 07, 2024
- Modified: Aug. 06, 2025
-
7.5
HIGHCVE-2024-5242
TP-Link Omada ER605 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not required to... Read more
- Published: May. 23, 2024
- Modified: Aug. 06, 2025
-
7.5
HIGHCVE-2024-5228
TP-Link Omada ER605 Comexe DDNS Response Handling Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Aut... Read more
- Published: May. 23, 2024
- Modified: Aug. 06, 2025
-
7.5
HIGHCVE-2024-5227
TP-Link Omada ER605 PPTP VPN username Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not req... Read more
- Published: May. 23, 2024
- Modified: Aug. 06, 2025
-
7.5
HIGHCVE-2025-20128
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underf... Read more
- Published: Jan. 22, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-8319
the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL parameter... Read more
Affected Products : message_archiver_firmware- Published: Jul. 30, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2020-3538
A vulnerability in a certain REST API endpoint of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to perform a path traversal attack on an affected device. The vulnerability is due to insufficient path... Read more
- Published: Nov. 18, 2024
- Modified: Aug. 06, 2025
-
5.4
MEDIUMCVE-2020-3420
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cros... Read more
Affected Products : unified_communications_manager- Published: Nov. 18, 2024
- Modified: Aug. 06, 2025