Latest CVE Feed
-
5.8
MEDIUMCVE-2025-53864
Connect2id Nimbus JOSE + JWT before 10.0.2 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the... Read more
Affected Products : nimbus_jose\+jwt- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Denial of Service
-
9.0
HIGHCVE-2025-7434
A vulnerability was found in Tenda FH451 up to 1.0.0.9 and classified as critical. Affected by this issue is the function fromAddressNat of the file /goform/addressNat of the component POST Request Handler. The manipulation of the argument page leads to s... Read more
- Published: Jul. 11, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-7423
A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). Affected by this vulnerability is the function formWifiMacFilterSet of the file /goform/setWrlFilterList of the component httpd. The manipulation of the argument macList leads ... Read more
- Published: Jul. 11, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-7422
A vulnerability classified as critical has been found in Tenda O3V2 1.0.0.12(3880). Affected is the function setAutoReboot of the file /goform/setNetworkService of the component httpd. The manipulation of the argument week leads to stack-based buffer over... Read more
- Published: Jul. 11, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-7421
A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been rated as critical. This issue affects the function fromMacFilterModify of the file /goform/operateMacFilter of the component httpd. The manipulation of the argument mac leads to stack-bas... Read more
- Published: Jul. 11, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-5241
Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series allows a remote unauthenticated attacker to lockout legitimate users for a certain period by repeatedly attempting to login with incorrect pas... Read more
Affected Products : melsec_iq-fx5u-32mt\/es_firmware melsec_iq-fx5u-32mt\/ds_firmware melsec_iq-fx5u-32mt\/ess_firmware melsec_iq-fx5u-32mt\/dss_firmware melsec_iq-fx5u-32mr\/es_firmware melsec_iq-fx5u-32mr\/ds_firmware melsec_iq-fx5u-64mt\/es_firmware melsec_iq-fx5u-64mt\/ds_firmware melsec_iq-fx5u-64mt\/ess_firmware melsec_iq-fx5u-64mt\/dss_firmware +11 more products- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authentication
-
9.0
HIGHCVE-2025-7420
A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been declared as critical. This vulnerability affects the function formWifiBasicSet of the file /goform/setWrlBasicInfo of the component httpd. The manipulation of the argument extChannel lead... Read more
- Published: Jul. 11, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-53519
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user's browser, p... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-53515
A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters are not ... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-53509
A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker with at least user-level privileges. An input parameter can be used directly in a comman... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-53475
A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters in th... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
5.9
MEDIUMCVE-2025-53471
Emerson ValveLink products receive input or data, but it do not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.... Read more
Affected Products :- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-53397
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in the user's browser, potentially l... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Cross-Site Scripting
-
9.4
CRITICALCVE-2025-52579
Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to disk, stored in a core dump, or remain uncleared if the product crashes, or if the programmer does not properly clear the memory befor... Read more
Affected Products :- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Cryptography
-
8.8
HIGHCVE-2025-52577
A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters ar... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-52459
A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters can be used directly in a command wit... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection
-
8.5
HIGHCVE-2025-50109
Emerson ValveLink Products store sensitive information in cleartext within a resource that might be accessible to another control sphere.... Read more
Affected Products :- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Information Disclosure
-
7.6
HIGHCVE-2025-48891
A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with at least user-level privileges, potentially leading to i... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
5.9
MEDIUMCVE-2025-48496
Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.... Read more
Affected Products :- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-46704
A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privileges. A specific parameter is not properl... Read more
Affected Products : iview- Published: Jul. 11, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Path Traversal