4.3

CVSS3.1

CVE-2024-8685 - Path-Traversal vulnerability in Revolution Pi

Path-Traversal vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated attacker to list device directories via the β€˜/pictory/php/getFileList.php’ endpoint in the β€˜dir’ parameter.

πŸ“… Published: Feb. 10, 2025, 12:46 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS3.1

CVE-2024-8684 - OS Command Injection vulnerability in Revolution Pi

OS Command Injection vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated attacker to execute OS commands on the device via the β€˜php/dal.php’ endpoint, in the β€˜arrSaveConfig’ parameter.

πŸ“… Published: Feb. 10, 2025, 12:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-1175 - Cross-Site Scripting (XSS) vulnerability in Kelio Visio

Reflected Cross-Site Scripting (XSS) vulnerability in Kelio Visio 1, Kelio Visio X7 and Kelio Visio X4, in versions between 3.2C and 5.1K. This vulnerability could allow an attacker to execute a JavaScript payload by making a POST request and injecting malicious code into the editable β€˜username’ pa…

πŸ“… Published: Feb. 10, 2025, 12:42 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-25247 - Apache Felix Webconsole: XSS in services console

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8. Users are recommended to upgrade to version 4.9.10 or 5.0.10 or higher, which fixes the is…

πŸ“… Published: Feb. 10, 2025, 11:16 a.m. πŸ”„ Last Modified: July 14, 2025, 1:50 p.m.

7

CVSS4.0

CVE-2025-1099 - Information Disclosure Vulnerability in TP-Link Tapo C500 Wi-Fi Camera

This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could exploit this vulnerability to obtain cryptographic private keys which can then be used to perform impersonation, data decryption and man …

πŸ“… Published: Feb. 10, 2025, 10:44 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-21687 - vfio/platform: check the bounds of read/write syscalls

In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write syscalls count and offset are passed from user space and not checked, only offset is capped to 40 bits, which can be used to read/write out of bounds of the device.

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:19 p.m.

8

CVSS3.1

CVE-2024-46431 -

Tenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can exploit this vulnerability by sending specially crafted data to the delWewifiPic function.

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 6:12 p.m.

4.7

CVSS3.1

CVE-2025-21688 - drm/v3d: Assign job pointer to NULL before signaling the fence

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Assign job pointer to NULL before signaling the fence In commit e4b5ccd392b9 ("drm/v3d: Ensure job pointer is set to NULL after job completion"), we introduced a change to assign the job pointer to NULL after completing …

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:19 p.m.

5.5

CVSS3.1

CVE-2025-21689 - USB: serial: quatech2: fix null-ptr-deref in qt2_process_read_urb()

In the Linux kernel, the following vulnerability has been resolved: USB: serial: quatech2: fix null-ptr-deref in qt2_process_read_urb() This patch addresses a null-ptr-deref in qt2_process_read_urb() due to an incorrect bounds check in the following: if (newport > serial->num_ports) { …

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:19 p.m.

8.8

CVSS3.1

CVE-2024-46434 -

Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gain administrative access by sending a specially crafted HTTP request.

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 6:13 p.m.
Total resulsts: 348023
Page 6693 of 34,803
Β« previous page Β» next page
Filters