Latest CVE Feed
-
5.5
MEDIUMCVE-2024-57545
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (hidden_dhcp_num) is copied to the stack without length verification.... Read more
- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
5.5
MEDIUMCVE-2024-57544
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (lan_ipaddr) is copied to the stack without length verification.... Read more
- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
5.5
MEDIUMCVE-2024-57543
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (dhcpstart_ip) is copied to the stack without length verification.... Read more
- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
8.8
HIGHCVE-2024-57542
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_btn.... Read more
- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
5.5
MEDIUMCVE-2024-57541
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (ipv6_protect_status) is copied to the stack without length verification.... Read more
- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
6.5
MEDIUMCVE-2024-57540
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (action) is copied to the stack without length verification.... Read more
- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
8.2
HIGHCVE-2024-57539
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail.... Read more
- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
6.5
MEDIUMCVE-2024-57538
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (anonymous_protect_status) is copied to the stack without length verification.... Read more
- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
6.3
MEDIUMCVE-2024-57537
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (page) is copied to the stack without length verification.... Read more
- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
8.0
HIGHCVE-2024-57536
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status.... Read more
- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
-
5.5
MEDIUMCVE-2024-57360
https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Mar. 18, 2025
-
9.1
CRITICALCVE-2024-55959
Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Mar. 18, 2025
-
4.8
MEDIUMCVE-2024-55958
Northern.tech CFEngine Enterprise Mission Portal 3.24.0, 3.21.5, and below allows XSS. The fixed versions are 3.24.1 and 3.21.6.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 22, 2025
-
5.4
MEDIUMCVE-2024-48392
OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into user email due to lack of input validation, which could lead to account takeover.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 22, 2025
-
5.4
MEDIUMCVE-2024-21245
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with networ... Read more
Affected Products : jd_edwards_enterpriseone_tools- Published: Jan. 21, 2025
- Modified: Mar. 17, 2025
-
9.1
CRITICALCVE-2025-24024
Mjolnir is a moderation tool for Matrix. Mjolnir v1.9.0 responds to management commands from any room the bot is member of. This can allow users who aren't operators of the bot to use the bot's functions, including server administration components if enab... Read more
Affected Products : mjolnir- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
9.8
CRITICALCVE-2024-42936
The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Execution via a modified MQTT broker message.... Read more
- Published: Jan. 21, 2025
- Modified: Jun. 18, 2025
-
6.1
MEDIUMCVE-2023-45908
Homarr before v0.14.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notebook widget.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
7.6
HIGHCVE-2025-23369
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unauthorized internal users. Instances not utilizing SAML single sign-on or where the attacker is not already... Read more
Affected Products : enterprise_server- Published: Jan. 21, 2025
- Modified: Feb. 05, 2025
-
5.5
MEDIUMCVE-2024-55504
An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote control and unauthorized access to sensitive user data via the exploit_combined.dylib component on MacOS.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Feb. 04, 2025