Latest CVE Feed
-
7.5
HIGHCVE-2025-22984
An access control issue in the component /api/squareComment/DelectSquareById of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.... Read more
Affected Products : icecms- Published: Jan. 14, 2025
- Modified: Apr. 18, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-22983
An access control issue in the component /square/getAllSquare/circle of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.... Read more
Affected Products : icecms- Published: Jan. 14, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-0461
A vulnerability has been found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as problematic. This vulnerability affects unknown code of the file /crm/weixinmp/index.php?userid=123&module=Users&usid=1&action=UsersAja... Read more
Affected Products : lingdang_crm- Published: Jan. 14, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-0460
A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file /index.php?route=extension/module/blog_add. The manipulation of the argument image leads to unrestricted ... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-0459
A vulnerability, which was classified as problematic, has been found in libretro RetroArch up to 1.19.1 on Windows. Affected by this issue is some unknown functionality in the library profapi.dll of the component Startup. The manipulation leads to untrust... Read more
Affected Products : retroarch- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
- Vuln Type: Misconfiguration
-
6.9
MEDIUMCVE-2025-0458
A vulnerability classified as problematic was found in Virtual Computer Vysual RH Solution 2024.12.1. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login Panel. The manipulation of the argument page lea... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.6
MEDIUMCVE-2024-29980
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix SecureCore™ for Intel Coffee Lake, Phoenix SecureCore™ for Intel Comet Lake, Phoenix SecureCore™ for Intel Ice Lake allows Input Data Ma... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jul. 28, 2025
-
4.6
MEDIUMCVE-2024-29979
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix SecureCore™ for Intel Coffee Lake, Phoenix SecureCore™ for Intel Comet Lake, Phoenix SecureCore™ for Intel Ice Lake allows Input Data Ma... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jul. 28, 2025
-
5.4
MEDIUMCVE-2024-55000
Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categories.php.... Read more
- Published: Jan. 14, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-42444
APTIOV contains a vulnerability in BIOS where an attacker may cause a TOCTOU Race Condition by local means. Successful exploitation of this vulnerability may lead to execution of arbitrary code on the target device.... Read more
Affected Products : aptio_v- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
- Vuln Type: Race Condition
-
9.1
CRITICALCVE-2024-39803
Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request t... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-39802
Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request t... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-39801
Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request t... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-39800
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authent... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2024-39799
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authent... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2024-39798
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authent... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2024-39795
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request ... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2024-39794
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request ... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2024-39793
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request ... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2024-39790
Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to t... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Misconfiguration