6.9
CVE-2025-0681 - New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symโฆ
The Cloud MQTT service of the affected products supports wildcard topic subscription which could allow an attacker to obtain sensitive information from tapping the service communications.
9.3
CVE-2025-0680 - New Rock Technologies Cloud Connected Devices has a Improper Neutralization of Special Elements useโฆ
Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected to the cloud.
7.8
CVE-2024-44142 -
The issue was addressed with improved bounds checks. This issue is fixed in GarageBand 10.4.12. Processing a maliciously crafted image may lead to arbitrary code execution.
8.9
CVE-2025-24507 -
This vulnerability allows appliance compromise at boot time.
5.3
CVE-2025-24506 -
A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.
8.8
CVE-2025-24505 -
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file.
5.3
CVE-2025-24504 -
An improper input validation the CSRF filter results in unsanitized user input written to the application logs.
9.3
CVE-2025-24503 -
A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.
5.3
CVE-2025-24502 -
An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.
5.3
CVE-2025-24501 -
An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.