Vulnerabilities (CVE)

Total 291487 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-51001 1 Netgear 2 R8500, R8500 Firmware 2025-04-22 N/A 5.7 MEDIUM
Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the sysDNSHost parameter at ddns.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVE-2024-51000 1 Netgear 2 R8500, R8500 Firmware 2025-04-22 N/A 5.7 MEDIUM
Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component wireless.cgi via the opmode, opmode_an, and opmode_an_2 parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVE-2024-50999 1 Netgear 2 R8500, R8500 Firmware 2025-04-22 N/A 5.7 MEDIUM
Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at password.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
CVE-2024-50998 1 Netgear 2 R8500, R8500 Firmware 2025-04-22 N/A 5.7 MEDIUM
Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component openvpn.cgi via the openvpn_service_port and openvpn_service_port_tun parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVE-2024-50995 1 Netgear 2 R8500, R8500 Firmware 2025-04-22 N/A 5.7 MEDIUM
Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVE-2024-50994 1 Netgear 2 R8500, R8500 Firmware 2025-04-22 N/A 5.7 MEDIUM
Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component ipv6_fix.cgi via the ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, and ipv6_lan_length parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVE-2024-50993 1 Netgear 2 R8500, R8500 Firmware 2025-04-22 N/A 8.0 HIGH
Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at admin_account.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
CVE-2025-28100 1 Geeeeeeeek 1 Dingfanzu 2025-04-22 N/A 9.8 CRITICAL
A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.
CVE-2023-46304 1 Vtiger 1 Vtiger Crm 2025-04-22 N/A 8.1 HIGH
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).
CVE-2024-30176 1 Logpoint 1 Siem 2025-04-22 N/A 5.3 MEDIUM
In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared widgets.
CVE-2024-34475 1 Open5gs 1 Open5gs 2025-04-22 N/A 7.5 HIGH
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR.
CVE-2024-34476 1 Open5gs 1 Open5gs 2025-04-22 N/A 5.3 MEDIUM
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for pkbuf->len.
CVE-2024-33382 1 Open5gs 1 Open5gs 2025-04-22 N/A 5.3 MEDIUM
An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration
CVE-2025-29705 1 Tanghc 1 Code-gen 2025-04-22 N/A 4.3 MEDIUM
code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone to access such projects.
CVE-2025-33026 1 Peazip 1 Peazip 2025-04-22 N/A 6.1 MEDIUM
In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of PeaZip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, PeaZip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user.
CVE-2024-24429 1 Open5gs 1 Open5gs 2025-04-22 N/A 8.6 HIGH
A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.
CVE-2024-24432 1 Open5gs 1 Open5gs 2025-04-22 N/A 5.3 MEDIUM
A reachable assertion in the ogs_kdf_hash_mme function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.
CVE-2024-24430 1 Open5gs 1 Open5gs 2025-04-22 N/A 7.5 HIGH
A reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.
CVE-2024-24431 1 Open5gs 1 Open5gs 2025-04-22 N/A 7.5 HIGH
A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet with a zero-length EMM message length.
CVE-2024-6857 1 Ngothang 1 Wp Multitasking 2025-04-22 N/A 4.3 MEDIUM
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its Header, Footer and Body Script Settings, which could allow attackers to make logged admins perform such action via a CSRF attack