Latest CVE Feed
-
4.8
MEDIUMCVE-2025-3994
A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been classified as problematic. Affected is an unknown function of the file /home.htm of the component IP Port Filtering. The manipulation of the argument Comment leads to cross site scr... Read more
- Published: Apr. 28, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-3993
A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initia... Read more
- Published: Apr. 28, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-3992
A vulnerability has been found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formWlwds. The manipulation of the argument submit-url leads to buffer overflow. The attack can be in... Read more
- Published: Apr. 28, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-3991
A vulnerability, which was classified as critical, was found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boafrm/formWdsEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initi... Read more
- Published: Apr. 28, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
6.9
MEDIUMCVE-2025-31144
Quick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication channel to intended endpoints. If exploited, a remote unauthenticated attacker may attempt to log in to an arbitrary host via Windows system where the product is... Read more
Affected Products :- Published: Apr. 28, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authentication
-
7.1
HIGHCVE-2025-27937
Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, an arbitrary file in the affected product may be obtained by a remote attacker who can log in to the prod... Read more
Affected Products :- Published: Apr. 28, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Path Traversal
-
9.2
CRITICALCVE-2025-26692
Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, arbitrary code may be executed by a remote unauthenticated attacker with the Windows system privilege whe... Read more
Affected Products :- Published: Apr. 28, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Path Traversal
-
9.0
HIGHCVE-2025-3990
A vulnerability, which was classified as critical, has been found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this issue is some unknown functionality of the file /boafrm/formVlan. The manipulation of the argument submit-url leads to buffer overflow. ... Read more
- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-3989
A vulnerability classified as critical was found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this vulnerability is an unknown functionality of the file /boafrm/formStaticDHCP. The manipulation of the argument Hostname leads to buffer overflow. The att... Read more
- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-46690
Ververica Platform 2.14.0 allows low-privileged users to access SQL connectors via a direct namespaces/default/formats request.... Read more
Affected Products : ververica_platform- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-46689
Ververica Platform 2.14.0 contain an Reflected XSS vulnerability via a namespaces/default/formats URI.... Read more
Affected Products : ververica_platform- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-3988
A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. Affected is an unknown function of the file /boafrm/formPortFw. The manipulation of the argument service_type leads to buffer overflow. It is possible to launch the ... Read more
- Published: Apr. 27, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-3987
A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of the argument localPin leads to command injection. The attack may be in... Read more
- Published: Apr. 27, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-3986
A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown code of the file cas-5.2.6\core\cas-server-core-configuration-metadata-repository\src\main\java\org\apereo\cas\metadata\rest\CasConfigur... Read more
Affected Products : central_authentication_service- Published: Apr. 27, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Denial of Service
-
5.1
MEDIUMCVE-2025-3985
A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function ResponseEntity of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\ManageRegisteredS... Read more
Affected Products : central_authentication_service- Published: Apr. 27, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Denial of Service
-
8.4
HIGHCVE-2025-46688
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.... Read more
- Published: Apr. 27, 2025
- Modified: May. 30, 2025
- Vuln Type: Memory Corruption
-
5.6
MEDIUMCVE-2025-46687
quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.... Read more
Affected Products : quickjs- Published: Apr. 27, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Memory Corruption
-
5.0
MEDIUMCVE-2025-3984
A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\RegisteredServiceSi... Read more
Affected Products : central_authentication_service- Published: Apr. 27, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-3983
A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manager/system/nlog_down.php. The manipulation of the argument ProtocolType lea... Read more
Affected Products : hotel_broadband_operating_system- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-3982
A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0. Affected is the function SvSetPropNodeMK2 of the file sverchok/nodes/object_nodes/getsetprop_mk2.py of the component Set Property Mk2 Node. The manipulation leads ... Read more
Affected Products : sverchok- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Misconfiguration