Latest CVE Feed
-
7.5
HIGHCVE-2025-8708
A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeManager of the file ShiroConfiguration.java of the component com.gm.wj.config.ShiroConfiguration. The manipul... Read more
Affected Products : white-jotter- Published: Aug. 08, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Misconfiguration
-
4.6
MEDIUMCVE-2025-50179
Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a cross-site request forgery vulnerability in Tuleap Community Edition prior to version 16.8.99.1749830289 and Tuleap Enterprise Edition... Read more
Affected Products : tuleap- Published: Jun. 25, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-53192
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Apache Commons OGNL: all versions. When using the API Ognl.getValue, the OGNL engine parses and evaluate... Read more
Affected Products : commons_ognl- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2024-39756
A buffer overflow vulnerability exists in the adm.cgi rep_as_router() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigg... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-39757
A stack-based buffer overflow vulnerability exists in the wireless.cgi AddMac() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP reques... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-39798
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authent... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2024-39799
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authent... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2024-39800
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authent... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2024-39801
Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request t... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-39802
Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request t... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-39803
Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request t... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
4.6
MEDIUMCVE-2025-48991
Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a vulnerability present in Tuleap Community Edition prior to version 16.8.99.1748845907 and Tuleap Enterprise Edition prior to versions ... Read more
Affected Products : tuleap- Published: Jun. 25, 2025
- Modified: Aug. 21, 2025
-
10.0
CRITICALCVE-2024-56731
Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve remote command execution due to an insufficient patch for CVE-2024-39931. Unprivileged user accounts can exec... Read more
Affected Products : gogs- Published: Jun. 24, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2024-36295
A command execution vulnerability exists in the qos.cgi qos_sta() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger t... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2024-36493
A stack-based buffer overflow vulnerability exists in the wireless.cgi set_wifi_basic() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTT... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-50054
Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large control message buffer to the kernel driver resulting in a system crash... Read more
Affected Products : ovpn-dco-win- Published: Jun. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-37184
A buffer overflow vulnerability exists in the adm.cgi rep_as_bridge() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigg... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-37186
An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to tri... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2024-37357
A buffer overflow vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger t... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-39603
A stack-based buffer overflow vulnerability exists in the wireless.cgi set_wifi_basic_mesh() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticate... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption