Latest CVE Feed
-
6.8
MEDIUMCVE-2025-31680
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: from 0.0.0 before 1.24.0.... Read more
- Published: Mar. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2025-31679
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Ignition Error Pages allows Cross-Site Scripting (XSS).This issue affects Ignition Error Pages: from 0.0.0 before 1.0.4.... Read more
- Published: Mar. 31, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
8.2
HIGHCVE-2025-31678
Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.3.... Read more
- Published: Mar. 31, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-31677
Cross-Site Request Forgery (CSRF) vulnerability in Drupal AI (Artificial Intelligence) allows Cross Site Request Forgery.This issue affects AI (Artificial Intelligence): from 1.0.0 before 1.0.2.... Read more
- Published: Mar. 31, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-31676
Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3.... Read more
Affected Products : email_tfa- Published: Mar. 31, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-31675
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 be... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-31674
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, fr... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: May. 01, 2025
- Vuln Type: Authentication
-
4.6
MEDIUMCVE-2025-31673
Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-26683
Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.... Read more
Affected Products : azure_playwright- Published: Mar. 31, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-3016
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImporter::ParseTextureColorData of the file code/AssetLib/MDL/MDLMaterialLoader.cpp of the component MDL File... Read more
Affected Products : assimp- Published: Mar. 31, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-3015
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the file code/AssetLib/ASE/ASELoader.cpp of the component ASE File Handler. The ma... Read more
Affected Products : assimp- Published: Mar. 31, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-54809
Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header function due to use of a request header parameter in a strncpy where size is determined based on the input specified. By sending a specia... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-54808
Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized t... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-54807
In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the NewInternalClient parameter of the AddPortMapping SOAPAction into a system call without sanitation. An attacker can ... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-54806
Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execution of system commands via the web interface.... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-54805
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter get_email. After which, they can visit the send_log.cgi endpoint which uses the parameter ... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-54804
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter wan_hostname and forcing a reboot. This will result in command injection.... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-54803
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter pppoe_peer_mac and forcing a reboot. This will result in command injection.... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-54802
In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow in the M-SEARCH Host header.... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
5.9
MEDIUMCVE-2024-24456
An E-RAB Release Command packet containing a malformed NAS PDU will cause the Athonet MME to immediately crash, potentially due to a buffer overflow.... Read more
Affected Products :- Published: Mar. 31, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Memory Corruption