Latest CVE Feed
-
9.0
HIGHCVE-2025-7421
A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been rated as critical. This issue affects the function fromMacFilterModify of the file /goform/operateMacFilter of the component httpd. The manipulation of the argument mac leads to stack-bas... Read more
- Published: Jul. 11, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-5241
Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series allows a remote unauthenticated attacker to lockout legitimate users for a certain period by repeatedly attempting to login with incorrect pas... Read more
Affected Products : melsec_iq-fx5u-32mt\/es_firmware melsec_iq-fx5u-32mt\/ds_firmware melsec_iq-fx5u-32mt\/ess_firmware melsec_iq-fx5u-32mt\/dss_firmware melsec_iq-fx5u-32mr\/es_firmware melsec_iq-fx5u-32mr\/ds_firmware melsec_iq-fx5u-64mt\/es_firmware melsec_iq-fx5u-64mt\/ds_firmware melsec_iq-fx5u-64mt\/ess_firmware melsec_iq-fx5u-64mt\/dss_firmware +11 more products- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authentication
-
9.0
HIGHCVE-2025-7420
A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been declared as critical. This vulnerability affects the function formWifiBasicSet of the file /goform/setWrlBasicInfo of the component httpd. The manipulation of the argument extChannel lead... Read more
- Published: Jul. 11, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-53519
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user's browser, p... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-53515
A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters are not ... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-53509
A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker with at least user-level privileges. An input parameter can be used directly in a comman... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-53475
A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters in th... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
5.9
MEDIUMCVE-2025-53471
Emerson ValveLink products receive input or data, but it do not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.... Read more
Affected Products :- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-53397
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in the user's browser, potentially l... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Cross-Site Scripting
-
9.4
CRITICALCVE-2025-52579
Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to disk, stored in a core dump, or remain uncleared if the product crashes, or if the programmer does not properly clear the memory befor... Read more
Affected Products :- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Cryptography
-
8.8
HIGHCVE-2025-52577
A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters ar... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-52459
A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters can be used directly in a command wit... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection
-
8.5
HIGHCVE-2025-50109
Emerson ValveLink Products store sensitive information in cleartext within a resource that might be accessible to another control sphere.... Read more
Affected Products :- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Information Disclosure
-
7.6
HIGHCVE-2025-48891
A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with at least user-level privileges, potentially leading to i... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
5.9
MEDIUMCVE-2025-48496
Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.... Read more
Affected Products :- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-46704
A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privileges. A specific parameter is not properl... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Path Traversal
-
8.5
HIGHCVE-2025-46358
Emerson ValveLink products do not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.... Read more
Affected Products :- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2025-41442
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute unauthorized scripts in the user's brows... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-7419
A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been classified as critical. This affects the function fromSpeedTestSet of the file /goform/setRateTest of the component httpd. The manipulation of the argument destIP leads to stack-based buf... Read more
- Published: Jul. 10, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-7418
A vulnerability was found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this issue is the function fromPingResultGet of the file /goform/setPing of the component httpd. The manipulation of the argument destIP leads to stack-based bu... Read more
- Published: Jul. 10, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Memory Corruption