Latest CVE Feed
-
6.5
MEDIUMCVE-2025-32890
An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. It uses a custom implementation of encryption without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the messa... Read more
- Published: May. 01, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Cryptography
-
6.1
MEDIUMCVE-2025-3900
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS).This issue affects Colorbox: from 0.0.0 before 2.1.3.... Read more
Affected Products : colorbox- Published: Apr. 23, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Cross-Site Scripting
-
4.7
MEDIUMCVE-2025-28355
Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none... Read more
Affected Products : personal_management_system- Published: Apr. 18, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.8
MEDIUMCVE-2024-48948
The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because ... Read more
- Published: Oct. 15, 2024
- Modified: Jun. 20, 2025
-
5.3
MEDIUMCVE-2025-5033
A vulnerability classified as problematic was found in XiaoBingby TeaCMS 2.0.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/me/teacms/controller/admin/UserManageController/addUser. The manipulation leads to cross-s... Read more
Affected Products : teacms- Published: May. 21, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2025-30194
When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by crafting a DoH exchange that triggers an illegal memory access (double-free) and crash of DNSdist, causing a denial of service. The remedy is... Read more
Affected Products : dnsdist- Published: Apr. 29, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2023-6129
Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications running on PowerPC CPU based platforms if the CPU provides vector instructions. Impact summary: If an attack... Read more
Affected Products : openssl- Published: Jan. 09, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-51970
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-51969
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function getIptvInfo.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-51967
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function getIptvInfo.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-51966
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-51965
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-51963
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-51953
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-51952
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2023-51252
PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html files containing malicious code are uploaded, an XSS popup window is realized through online viewing.... Read more
Affected Products : publiccms- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-51126
Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-51123
An issue discovered in D-Link dir815 v.1.01SSb08.bin allows a remote attacker to execute arbitrary code via a crafted POST request to the service parameter in the soapcgi_main function of the cgibin binary component.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-49237
An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.... Read more
- Published: Jan. 09, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-49236
A stack-based buffer overflow was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices, leading to arbitrary command execution. This occurs because of lack of length validation during an sscanf of a user-entered scale field in the RTSP playback functio... Read more
- Published: Jan. 09, 2024
- Modified: Jun. 20, 2025