Latest CVE Feed
-
6.5
MEDIUMCVE-2025-9186
Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability affects Firefox < 142.... Read more
Affected Products : firefox- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Misconfiguration
-
7.6
HIGHCVE-2025-8361
Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing.This issue affects Config Pages: from 0.0.0 before 2.18.0.... Read more
Affected Products : config_pages- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-9187
Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-9169
A vulnerability was determined in SolidInvoice up to 2.4.0. Impacted is an unknown function of the file /quotes of the component Quote Module. This manipulation of the argument Name causes cross site scripting. Remote exploitation of the attack is possibl... Read more
Affected Products : solidinvoice- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-9170
A vulnerability was identified in SolidInvoice up to 2.4.0. The affected element is an unknown function of the file /tax/rates of the component Tax Rates Module. Such manipulation of the argument Name leads to cross site scripting. The attack can be execu... Read more
Affected Products : solidinvoice- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-9171
A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file /clients of the component Clients Module. Performing manipulation of the argument Name results in cross site scripting. The attack is ... Read more
Affected Products : solidinvoice- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-8362
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GoogleTag Manager allows Cross-Site Scripting (XSS).This issue affects GoogleTag Manager: from 0.0.0 before 1.10.0.... Read more
Affected Products : googletag_manager- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-9132
Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
6.3
MEDIUMCVE-2024-39954
CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. allows the attacker can abuse functionality on the server to read or update internal resources. Users are recommended to upgrade to ver... Read more
Affected Products : eventmesh- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Server-Side Request Forgery
-
9.8
CRITICALCVE-2025-24322
An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted network request can lead to arbitrary code execution. An attacker can browse to the device to trig... Read more
- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-24496
An information disclosure vulnerability exists in the /goform/getproductInfo functionality of Tenda AC6 V5.0 V02.03.01.110. Specially crafted network packets can lead to a disclosure of sensitive information. An attacker can send packets to trigger this v... Read more
- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-27129
An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send packets to trigger this vulnerability.... Read more
- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2024-4507
A vulnerability was found in Ruijie RG-UAC up to 20240428 and classified as critical. This issue affects some unknown processing of the file /view/IPV6/ipv6StaticRoute/static_route_add_ipv6.php. The manipulation of the argument text_prefixlen/text_gateway... Read more
- Published: May. 06, 2024
- Modified: Aug. 21, 2025
-
8.6
HIGHCVE-2025-30256
A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted series of HTTP requests can lead to a reboot. An attacker can send multiple network packets to trigger this vulnerabilit... Read more
- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-31355
A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted malicious file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vu... Read more
- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-32010
A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP response can lead to arbitrary code execution. An attacker can send an HTTP response to trigger this vulnerability.... Read more
- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-55499
Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTime function.... Read more
- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
7.2
HIGHCVE-2024-4255
A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240419. This issue affects some unknown processing of the file /view/network Config/GRE/gre_edit_commit.php. The manipulation of the argument name leads to os comma... Read more
Affected Products : rg-uac_firmware rg-uac_6000-e50_firmware rg-uac rg-uac_6000-e50 rg-uac_6000-cc_firmware rg-uac_6000-cc rg-uac_6000-e10_firmware rg-uac_6000-e10 rg-uac_6000-e10c_firmware rg-uac_6000-e10c +46 more products- Published: Apr. 27, 2024
- Modified: Aug. 21, 2025
-
7.2
HIGHCVE-2024-4508
A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been classified as critical. Affected is an unknown function of the file /view/IPV6/ipv6StaticRoute/static_route_edit_ipv6.php. The manipulation of the argument oldipmask/oldgateway/olddevn... Read more
Affected Products : rg-uac_firmware rg-uac_6000-e50_firmware rg-uac rg-uac_6000-e50 rg-uac_6000-cc_firmware rg-uac_6000-cc rg-uac_6000-e10_firmware rg-uac_6000-e10 rg-uac_6000-e10c_firmware rg-uac_6000-e10c +46 more products- Published: May. 06, 2024
- Modified: Aug. 21, 2025
-
7.2
HIGHCVE-2024-4509
A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view/IPV6/naborTable/add_commit.php. The manipulation of the argument ip_addr/mac_addr lea... Read more
Affected Products : rg-uac_firmware rg-uac_6000-e50_firmware rg-uac rg-uac_6000-e50 rg-uac_6000-cc_firmware rg-uac_6000-cc rg-uac_6000-e10_firmware rg-uac_6000-e10 rg-uac_6000-e10c_firmware rg-uac_6000-e10c +46 more products- Published: May. 06, 2024
- Modified: Aug. 21, 2025