Latest CVE Feed
-
7.1
HIGHCVE-2024-45068
Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.3-00; Hitachi Ops Center OVA: from 10.9.3-00 before 1... Read more
Affected Products : ops_center_common_services- Published: Dec. 03, 2024
- Modified: Dec. 03, 2024
-
7.2
HIGHCVE-2024-9200
A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions through V5.15(ABQA.2.2)C0 could allow an authenticated attacker with administrator privileges to execute opera... Read more
Affected Products : vmg4005-b50a_firmware vmg4005-b60a_firmware emg6726-b10a_firmware vmg3927-b50b_firmware vmg4927-b50a_firmware vmg4005-b60a vmg4005-b50a emg6726-b10a vmg3927-b50b vmg4927-b50a +2 more products- Published: Dec. 03, 2024
- Modified: Jan. 21, 2025
-
4.9
MEDIUMCVE-2024-9197
A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated attacker with administrator privileges to cause a temporary den... Read more
- Published: Dec. 03, 2024
- Modified: Jan. 21, 2025
-
7.5
HIGHCVE-2024-8748
A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temporary denial of service (DoS) condition against the web ma... Read more
Affected Products : lte7480-m804_firmware lte7490-m904_firmware nebula_nr7101_firmware nr7101_firmware nr7102_firmware nebula_nr5101_firmware dx3301-t0_firmware dx4510-b1_firmware dx5401-b0_firmware emg3525-t50b_firmware +116 more products- Published: Dec. 03, 2024
- Modified: Jan. 21, 2025
-
5.5
MEDIUMCVE-2018-9449
In process_service_search_attr_rsp of sdp_discovery.cc, there is a possible out of bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for... Read more
Affected Products : android- Published: Dec. 03, 2024
- Modified: Dec. 18, 2024
-
5.5
MEDIUMCVE-2018-9441
In sdp_copy_raw_data of sdp_discovery.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.... Read more
Affected Products : android- Published: Dec. 03, 2024
- Modified: Dec. 18, 2024
-
8.8
HIGHCVE-2024-53937
An issue was discovered on Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by default with admin/admin as default credentials and is exposed over the LAN. The allows attackers to execute ar... Read more
Affected Products :- Published: Dec. 02, 2024
- Modified: Dec. 03, 2024
-
6.1
MEDIUMCVE-2024-53988
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with cer... Read more
- Published: Dec. 02, 2024
- Modified: Aug. 15, 2025
-
6.1
MEDIUMCVE-2024-53987
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with cer... Read more
- Published: Dec. 02, 2024
- Modified: Aug. 15, 2025
-
6.1
MEDIUMCVE-2024-53986
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with cer... Read more
- Published: Dec. 02, 2024
- Modified: Aug. 15, 2025
-
6.1
MEDIUMCVE-2024-53985
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0 and Nokogiri < 1.15.7, or 1.16.x < 1.1... Read more
- Published: Dec. 02, 2024
- Modified: Aug. 15, 2025
-
8.8
HIGHCVE-2024-53941
An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default Wi-Fi PSK value via the last 4 octets of the BSSID.... Read more
Affected Products :- Published: Dec. 02, 2024
- Modified: Dec. 03, 2024
-
8.8
HIGHCVE-2024-53940
An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. Certain /cgi-bin/luci/admin endpoints are vulnerable to command injection. Attackers can exploit this by sending crafted payloads through parame... Read more
Affected Products :- Published: Dec. 02, 2024
- Modified: Dec. 03, 2024
-
8.8
HIGHCVE-2024-53939
An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allow... Read more
Affected Products :- Published: Dec. 02, 2024
- Modified: Dec. 03, 2024
-
8.8
HIGHCVE-2024-53938
An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by default and exposed over the LAN. The root account is accessible without a password, allowing attackers to achi... Read more
Affected Products :- Published: Dec. 02, 2024
- Modified: Dec. 03, 2024
-
8.0
HIGHCVE-2024-53375
An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exists in the "tmp_get_sites" function of the HomeShield functionality provided by TP-Link. This vulnerability is still exploitable withou... Read more
Affected Products : archer_axe75_firmware- Published: Dec. 02, 2024
- Modified: Dec. 17, 2024
-
6.2
MEDIUMCVE-2018-9435
In gatt_process_error_rsp of gatt_cl.cc, there is a possible out of bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Dec. 02, 2024
- Modified: Dec. 18, 2024
-
7.8
HIGHCVE-2018-9431
In OSUInfo of OSUInfo.java, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Dec. 02, 2024
- Modified: Dec. 18, 2024
-
9.8
CRITICALCVE-2018-9430
In prop2cfg of btif_storage.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Dec. 02, 2024
- Modified: Dec. 18, 2024
-
6.5
MEDIUMCVE-2018-9429
In buildImageItemsIfPossible of ItemTable.cpp there is a possible out of bound read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.... Read more
Affected Products : android- Published: Dec. 02, 2024
- Modified: Dec. 18, 2024