Search

Search Results (320085 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-50596 1 Dlink 2 Dir-1260, Dir-1260 Firmware 2025-11-28 9.8 Critical
D-Link DIR-1260 Wi-Fi router firmware versions up to and including v1.20B05 contain a command injection vulnerability within the web management interface that allows for unauthenticated attackers to execute arbitrary commands on the device with root privileges. The flaw specifically exists within the SetDest/Dest/Target arguments to the GetDeviceSettings form. The management interface is accessible over HTTP and HTTPS on the local and Wi-Fi networks and optionally from the Internet.
CVE-2025-34247 1 Advantech 2 Webaccess/vpn, Webaccess\/vpn 2025-11-28 6.5 Medium
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
CVE-2025-34246 1 Advantech 2 Webaccess/vpn, Webaccess\/vpn 2025-11-28 6.5 Medium
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
CVE-2023-5844 1 Pimcore 1 Admin Classic Bundle 2025-11-28 7.2 High
Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0.
CVE-2025-34244 1 Advantech 2 Webaccess/vpn, Webaccess\/vpn 2025-11-28 6.5 Medium
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDeviceFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
CVE-2025-34243 1 Advantech 2 Webaccess/vpn, Webaccess\/vpn 2025-11-28 6.5 Medium
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetworkFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
CVE-2025-34242 1 Advantech 2 Webaccess/vpn, Webaccess\/vpn 2025-11-28 6.5 Medium
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetworkController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
CVE-2025-34241 1 Advantech 2 Webaccess/vpn, Webaccess\/vpn 2025-11-28 6.5 Medium
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDeviceAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
CVE-2025-34240 1 Advantech 2 Webaccess/vpn, Webaccess\/vpn 2025-11-28 6.5 Medium
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
CVE-2024-53015 1 Qualcomm 182 Aqt1000, Aqt1000 Firmware, Fastconnect 6200 and 179 more 2025-11-28 6.6 Medium
Memory corruption while processing IOCTL command to handle buffers associated with a session.
CVE-2024-53010 1 Qualcomm 386 Aqt1000, Aqt1000 Firmware, Ar8035 and 383 more 2025-11-28 7.8 High
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
CVE-2024-53020 1 Qualcomm 468 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 465 more 2025-11-28 8.2 High
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
CVE-2025-21483 1 Qualcomm 455 Apq8017, Apq8017 Firmware, Apq8064au and 452 more 2025-11-28 9.8 Critical
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
CVE-2025-27034 1 Qualcomm 227 315 5g Iot Modem, 315 5g Iot Modem Firmware, Ar8035 and 224 more 2025-11-28 9.8 Critical
Memory corruption while selecting the PLMN from SOR failed list.
CVE-2025-34236 1 Advantech 2 Webaccess/vpn, Webaccess\/vpn 2025-11-28 5.4 Medium
Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via NetworksController.addNetworkAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
CVE-2025-34237 1 Advantech 2 Webaccess/vpn, Webaccess\/vpn 2025-11-28 5.4 Medium
Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via StandaloneVpnClientsController.addStandaloneVpnClientAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
CVE-2025-52584 1 Ashlar 5 Argon, Cobalt, Cobalt Share and 2 more 2025-11-28 7.8 High
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing XE files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
CVE-2025-46269 1 Ashlar 5 Argon, Cobalt, Cobalt Share and 2 more 2025-11-28 7.8 High
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing VC6 files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
CVE-2025-53705 1 Ashlar 5 Argon, Cobalt, Cobalt Share and 2 more 2025-11-28 7.8 High
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing CO files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
CVE-2025-41392 1 Ashlar 5 Argon, Cobalt, Cobalt Share and 2 more 2025-11-28 7.8 High
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing AR files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.