Latest CVE Feed
-
6.5
MEDIUMCVE-2025-4175
A vulnerability, which was classified as critical, was found in AlanBinu007 Spring-Boot-Advanced-Projects up to 3.1.3. This affects the function uploadUserProfileImage of the file /Spring-Boot-Advanced-Projects-main/Project-4.SpringBoot-AWS-S3/backend/src... Read more
Affected Products :- Published: May. 01, 2025
- Modified: May. 10, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-48907
Sematell ReplyOne 7.4.3.0 allows SSRF via the application server API.... Read more
Affected Products : replyone- Published: May. 01, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Server-Side Request Forgery
-
6.1
MEDIUMCVE-2024-48906
Sematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name.... Read more
Affected Products : replyone- Published: May. 01, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2024-48905
Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.... Read more
Affected Products : replyone- Published: May. 01, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration
-
7.1
HIGHCVE-2025-46635
An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces on the router allows an attacker (who is authenticated to the guest Wi-Fi) to access resources on the rou... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Misconfiguration
-
8.2
HIGHCVE-2025-46634
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated attacker to authenticate to the web management portal by collecting credentials from observed/collected traffic. It ... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Authentication
-
8.2
HIGHCVE-2025-46633
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic between the client and server by collecting the symmetric AES key from collected and/or observed traffic. T... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Cryptography
-
6.5
MEDIUMCVE-2025-46632
Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or more easily decrypt encrypted messages between client and server.... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Cryptography
-
6.5
MEDIUMCVE-2025-46631
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet access to the router's OS by sending a /goform/telnet web request.... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-46630
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a remote system management binary) by sending a /goform/ate web request.... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-46629
Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthorized configuration changes for any router where 'ate' has been enabled by sending a crafted UDP packet... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Authentication
-
7.3
HIGHCVE-2025-46628
Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain root shell access to the device by sending a crafted UDP packet to the 'ate' service when it is enabled. ... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Authentication
-
8.2
HIGHCVE-2025-46627
Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/oc... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Authentication
-
7.3
HIGHCVE-2025-46626
Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt, replay, and/or forge traffic to the service.... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Cryptography
-
8.8
HIGHCVE-2025-46625
Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web reque... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
7.4
HIGHCVE-2025-46569
Open Policy Agent (OPA) is an open source, general-purpose policy engine. Prior to version 1.4.0, when run as a server, OPA exposes an HTTP Data API for reading and writing documents. Requesting a virtual document through the Data API entails policy evalu... Read more
Affected Products : open_policy_agent- Published: May. 01, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4174
A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql inje... Read more
Affected Products : covid19_testing_management_system- Published: May. 01, 2025
- Modified: May. 09, 2025
- Vuln Type: Injection
-
6.3
MEDIUMCVE-2025-3517
Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM user to elevate a previously configured user configured in a PAM JIT account via failure to update the internal account’s SID when updati... Read more
Affected Products : devolutions_server- Published: May. 01, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-36558
KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for authentication. If an attacker provides the user with a PiCtory URL containing an HTML script as an sso_token, that script will reply to t... Read more
Affected Products :- Published: May. 01, 2025
- Modified: May. 02, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-36521
MicroDicom DICOM Viewer is vulnerable to an out-of-bounds read which may allow an attacker to cause memory corruption within the application. The user must open a malicious DCM file for exploitation.... Read more
Affected Products : dicom_viewer- Published: May. 01, 2025
- Modified: May. 02, 2025
- Vuln Type: Memory Corruption