Search Results (30667 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-29135 1 Tenda 2 Ac7, Ac7 Firmware 2025-04-01 9.8 Critical
A stack-based buffer overflow vulnerability in Tenda AC7 V15.03.06.44 allows a remote attacker to execute arbitrary code through a stack overflow attack using the security parameter of the formWifiBasicSet function.
CVE-2025-29310 1 Opennetworking 1 Onos 2025-04-01 9.8 Critical
An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute arbitrary commands or access network information.
CVE-2025-29312 1 Opennetworking 1 Onos 2025-04-01 9.1 Critical
An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing the link type from indirect to direct.
CVE-2024-50667 1 Trendnet 2 Tew-820ap, Tew-820ap Firmware 2025-04-01 9.8 Critical
The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not sufficient, which allows attackers to construct payloads for attacks.
CVE-2024-42813 1 Trendnet 2 Tew-752dru, Tew-752dru Firmware 2025-04-01 9.8 Critical
In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
CVE-2024-29303 1 Mayurik 1 Php Task Management System 2025-04-01 9.8 Critical
The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection
CVE-2024-29661 1 Dedecms 1 Dedecms 2025-04-01 9.8 Critical
A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.
CVE-2024-33749 1 Dedecms 1 Dedecms 2025-04-01 9.1 Critical
DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.
CVE-2024-35375 1 Dedecms 1 Dedecms 2025-04-01 9.8 Critical
There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS
CVE-2024-35510 1 Dedecms 1 Dedecms 2025-04-01 9.8 Critical
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-29684 1 Dedecms 1 Dedecms 2025-04-01 9.8 Critical
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a remote attacker to execute arbitrary code.
CVE-2024-4764 1 Mozilla 1 Firefox 2025-04-01 9.8 Critical
Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.
CVE-2024-2862 1 Lg 1 Lg Led Assistant 2025-04-01 9.1 Critical
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
CVE-2024-29943 1 Mozilla 1 Firefox 2025-04-01 9.8 Critical
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.
CVE-2025-26002 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-04-01 9.8 Critical
Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setSyncTimeHost.
CVE-2025-26003 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-04-01 9.8 Critical
Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.
CVE-2025-26004 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-04-01 9.8 Critical
Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack buffer overflow vulnerability when requesting admin.cgi parameter with setDdns.
CVE-2024-55964 1 Appsmith 1 Appsmith 2025-04-01 9.8 Critical
An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command execution inside the Appsmith Docker container. The attacker must be able to access Appsmith, login to it, create a datasource, create a query against that datasource, and execute that query.
CVE-2025-26005 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-04-01 9.8 Critical
Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack overflow vulnerability when requesting admin.cgi parameter with setNtp.
CVE-2025-26006 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-04-01 9.8 Critical
Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setAutorest.