High · CVSS 7.5
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the schedEndTime parameter in the setSchedWifi function.
Published Dec 2, 2022 · Updated Apr 24, 2025
High · CVSS 7.5
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat function.
Published Dec 2, 2022 · Updated Apr 24, 2025
High · CVSS 8.8
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. A non-privileged user may escape a restricted shell and execute privileged commands.
Published Dec 4, 2022 · Updated Apr 24, 2025
High · CVSS 8.8
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Authenticated remote command execution can occur via the management portal.
Published Dec 4, 2022 · Updated Apr 24, 2025
High · CVSS 7.5
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the setSmartPowerManagement function.
Published Dec 2, 2022 · Updated Apr 24, 2025
High · CVSS 7.5
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.
Published Dec 2, 2022 · Updated Apr 24, 2025
High · CVSS 7.5
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDget function.
Published Dec 2, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.5
Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
Published Dec 2, 2022 · Updated Apr 24, 2025
High · CVSS 7.5
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterGet function.
Published Dec 2, 2022 · Updated Apr 24, 2025
High · CVSS 7.5
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.
Published Dec 2, 2022 · Updated Apr 24, 2025
High · CVSS 7.5
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the appData parameter in the formSetAppFilterRule function.
Published Dec 2, 2022 · Updated Apr 24, 2025
High · CVSS 7.5
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the formWx3AuthorizeSet function.
Published Dec 2, 2022 · Updated Apr 24, 2025
High · CVSS 7.5
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the endIp parameter in the formSetPPTPServer function.
Published Dec 2, 2022 · Updated Apr 24, 2025
High · CVSS 7.5
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the firewallEn parameter in the formSetFirewallCfg function.
Published Dec 2, 2022 · Updated Apr 24, 2025
High · CVSS 7.5
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the schedStartTime parameter in the setSchedWifi function.
Published Dec 2, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.5
Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.
Published Dec 2, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.5
Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
Published Dec 2, 2022 · Updated Apr 24, 2025
Medium · CVSS 4.3
A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow injection of response headers with %0d. This is fixed in pve-http-server 4.1-3.
Published Dec 4, 2022 · Updated Apr 24, 2025
Critical · CVSS 9.8
Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on the server. Also, in Proxmox Mail Gateway, privilege escalation to the root@pam account is possible if the backup feature has ever been used, because backup files such as pmg-backup_YYYY_MM_DD_*.tgz have 0644 permissions and contain an authkey value. This is fixed in pve-http-server 4.1-3.
Published Dec 4, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.1
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
Published Dec 4, 2022 · Updated Apr 24, 2025
High · CVSS 7.5
Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, such that there is uncontrolled recursion of attacker-generated messages.
Published Dec 4, 2022 · Updated Apr 24, 2025
High · CVSS 8.8
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root by using specific commands.
Published Dec 4, 2022 · Updated Apr 24, 2025
High · CVSS 8.8
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.
Published Dec 4, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In widevine, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446207; Issue ID: ALPS07446207.
Published Dec 5, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In widevine, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446213; Issue ID: ALPS07446213.
Published Dec 5, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In widevine, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446228; Issue ID: ALPS07446228.
Published Dec 5, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In widevine, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446228; Issue ID: ALPS07446228.
Published Dec 5, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In keyinstall, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07439659; Issue ID: ALPS07439659.
Published Dec 5, 2022 · Updated Apr 24, 2025
Critical · CVSS 9.8
Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setSnmpInfo.
Published Dec 2, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In mpu, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07541753; Issue ID: ALPS07541753.
Published Dec 5, 2022 · Updated Apr 24, 2025
Critical · CVSS 9.8
Tenda i21 V1.0.0.14(4656) has a stack overflow vulnerability via /goform/setSysPwd.
Published Dec 2, 2022 · Updated Apr 24, 2025
Critical · CVSS 9.8
Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setDiagnoseInfo.
Published Dec 2, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.4
In isp, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310829; Issue ID: ALPS07310829.
Published Dec 5, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In throttling, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07405923; Issue ID: ALPS07405923.
Published Dec 5, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In gz, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363786; Issue ID: ALPS07363786.
Published Dec 5, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In display, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326216; Issue ID: ALPS07326216.
Published Dec 5, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In display, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326239; Issue ID: ALPS07326239.
Published Dec 5, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310780; Issue ID: ALPS07310780.
Published Dec 5, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310774; Issue ID: ALPS07310774.
Published Dec 5, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In throttling, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07405966; Issue ID: ALPS07405966.
Published Dec 5, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453613; Issue ID: ALPS07453613.
Published Dec 5, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441630; Issue ID: ALPS07441630.
Published Dec 5, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441637; Issue ID: ALPS07441637.
Published Dec 5, 2022 · Updated Apr 24, 2025
Medium · CVSS 6.7
In ccci, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138646; Issue ID: ALPS07138646.
Published Dec 5, 2022 · Updated Apr 24, 2025
High · CVSS 7.5
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1.
Published Dec 5, 2022 · Updated Apr 24, 2025
High · CVSS 8.1
An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication.
Published Dec 5, 2022 · Updated Apr 24, 2025
Critical · CVSS 9.1
When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this as an invalid login attempt which can result in a Denial of Service (DoS) for the user if services like fail2ban are used.
Published Dec 5, 2022 · Updated Apr 24, 2025
Critical · CVSS 9.8
Buffer overflow in firmware lewei_cam binary version 2.0.10 in Force 1 Discovery Wifi U818A HD+ FPV Drone allows attacker to gain remote code execution as root user via a specially crafted UDP packet. Please update the Reference section to these links > http://thiscomputer.com/ > https://www.bostoncyber.org/ > https://medium.com/@meekworth/exploiting-the-lw9621-drone-camera-module-773f00081368
Published Dec 5, 2022 · Updated Apr 24, 2025
Critical · CVSS 9.8
OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.61 and earlier allows a remote attacker to execute an arbitrary OS command when processing compression and decompression on the product.
Published Dec 5, 2022 · Updated Apr 24, 2025
High · CVSS 7.5
Improper check or handling of exceptional conditions vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to inject an invalid value to decodeURIComponent of nako3edit, which may lead the server to crash.
Published Dec 5, 2022 · Updated Apr 24, 2025