6.9

CVSS4.0

CVE-2025-0681 - New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symโ€ฆ

The Cloud MQTT service of the affected products supports wildcard topic subscription which could allow an attacker to obtain sensitive information from tapping the service communications.

๐Ÿ“… Published: Jan. 30, 2025, 6:53 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-0680 - New Rock Technologies Cloud Connected Devices has a Improper Neutralization of Special Elements useโ€ฆ

Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected to the cloud.

๐Ÿ“… Published: Jan. 30, 2025, 6:50 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-44142 -

The issue was addressed with improved bounds checks. This issue is fixed in GarageBand 10.4.12. Processing a maliciously crafted image may lead to arbitrary code execution.

๐Ÿ“… Published: Jan. 30, 2025, 6:49 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 6:18 p.m.

8.9

CVSS4.0

CVE-2025-24507 -

This vulnerability allows appliance compromise at boot time.

๐Ÿ“… Published: Jan. 30, 2025, 6:41 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-24506 -

A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.

๐Ÿ“… Published: Jan. 30, 2025, 6:39 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-24505 -

This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file.

๐Ÿ“… Published: Jan. 30, 2025, 6:36 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-24504 -

An improper input validation the CSRF filter results in unsanitized user input written to the application logs.

๐Ÿ“… Published: Jan. 30, 2025, 6:31 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-24503 -

A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.

๐Ÿ“… Published: Jan. 30, 2025, 6:27 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-24502 -

An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.

๐Ÿ“… Published: Jan. 30, 2025, 6:24 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-24501 -

An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.

๐Ÿ“… Published: Jan. 30, 2025, 6:21 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6904 of 34,919
ยซ previous page ยป next page
Filters