Latest CVE Feed
-
9.1
CRITICALCVE-2024-39799
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authent... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2024-39800
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authent... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2024-39801
Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request t... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-39802
Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request t... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-39803
Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request t... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
4.6
MEDIUMCVE-2025-48991
Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a vulnerability present in Tuleap Community Edition prior to version 16.8.99.1748845907 and Tuleap Enterprise Edition prior to versions ... Read more
Affected Products : tuleap- Published: Jun. 25, 2025
- Modified: Aug. 21, 2025
-
10.0
CRITICALCVE-2024-56731
Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve remote command execution due to an insufficient patch for CVE-2024-39931. Unprivileged user accounts can exec... Read more
Affected Products : gogs- Published: Jun. 24, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2024-36295
A command execution vulnerability exists in the qos.cgi qos_sta() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger t... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2024-36493
A stack-based buffer overflow vulnerability exists in the wireless.cgi set_wifi_basic() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTT... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-50054
Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large control message buffer to the kernel driver resulting in a system crash... Read more
Affected Products : ovpn-dco-win- Published: Jun. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-37184
A buffer overflow vulnerability exists in the adm.cgi rep_as_bridge() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigg... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-37186
An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to tri... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2024-37357
A buffer overflow vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger t... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-39603
A stack-based buffer overflow vulnerability exists in the wireless.cgi set_wifi_basic_mesh() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticate... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.0
CRITICALCVE-2024-39604
A command execution vulnerability exists in the update_filter_url.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can perform a man-in-the-middle attack to trigge... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2024-39608
A firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary firmware update. An attacker can send an unauthenticated message to trigger this vulnerabili... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2024-39754
A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of network packets can lead to root access. An attacker can send packets to trigger this vulnerability.... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2018-25032
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.... Read more
Affected Products : fedora debian_linux active_iq_unified_manager h410c_firmware ontap_select_deploy_administration_utility macos mariadb oncommand_workflow_automation e-series_santricity_os_controller h300s_firmware +29 more products- EPSS Score: %0.09
- Published: Mar. 25, 2022
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2025-5309
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.... Read more
- Published: Jun. 16, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1113
A vulnerability was found in taisan tarzan-cms up to 1.0.0. It has been rated as critical. This issue affects the function upload of the file /admin#themes of the component Add Theme Handler. The manipulation leads to deserialization. The attack may be in... Read more
Affected Products : tarzan-cms- Published: Feb. 07, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Misconfiguration