CVE-2024-56190 - Linksys Wireless Router Out-of-Bounds Write Vulnerability
CVE ID : CVE-2024-56190
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2024-56190
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36903 - Lwis Buffer Write OOB Read/Write Vulnerability
CVE ID : CVE-2025-36903
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36903
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36894 - Apache TBD HTTP Denial of Service
CVE ID : CVE-2025-36894
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36894
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9516 - Atec Debug Plugin Arbitrary File Read Vulnerability in WordPress
CVE ID : CVE-2025-9516
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : The atec Debug plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.22 via the 'custom_log' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to view the contents of files outside of the originally intended directory.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-9516
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : The atec Debug plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.22 via the 'custom_log' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to view the contents of files outside of the originally intended directory.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36909 - Apache Struts SSRF
CVE ID : CVE-2025-36909
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : Information disclosure
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36909
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : Information disclosure
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36891 - Apache HTTP Server Local File Inclusion
CVE ID : CVE-2025-36891
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : Elevation of privilege
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36891
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : Elevation of privilege
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36896 - Apache Struts Deserialization RCE
CVE ID : CVE-2025-36896
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : N/A
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36896
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : N/A
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36893 - Apache ReadTachyonCommands Uninitialized Data Information Leak
CVE ID : CVE-2025-36893
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In ReadTachyonCommands of gxp_main_actor.cc, there is a possible information leak due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36893
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In ReadTachyonCommands of gxp_main_actor.cc, there is a possible information leak due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36907 - Qualcomm ABL Android Heap Buffer Overflow
CVE ID : CVE-2025-36907
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege via USB fastboot, after a bootloader unlock, with no additional execution privileges needed. User interaction is needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36907
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege via USB fastboot, after a bootloader unlock, with no additional execution privileges needed. User interaction is needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36899 - Apache HTTP Server Privilege Escalation Vulnerability
CVE ID : CVE-2025-36899
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36899
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36900 - "Logitech Wi-Fi Smart Code Vulnerability - Integer Overflow"
CVE ID : CVE-2025-36900
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In lwis_test_register_io of lwis_device_test.c, there is a possible OOB Write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36900
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In lwis_test_register_io of lwis_device_test.c, there is a possible OOB Write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36887 - Linksys Wi-Fi Router Out-of-Bounds Write Vulnerability
CVE ID : CVE-2025-36887
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In wl_cfgscan_update_v3_schedscan_results() of wl_cfgscan.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36887
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In wl_cfgscan_update_v3_schedscan_results() of wl_cfgscan.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41046 - Stored Cross-Site Scripting vulnerability in appRain CMF
CVE ID : CVE-2025-41046
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/960grid.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-41046
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/960grid.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41047 - Stored Cross-Site Scripting vulnerability in appRain CMF
CVE ID : CVE-2025-41047
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/ace.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-41047
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/ace.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41048 - Stored Cross-Site Scripting vulnerability in appRain CMF
CVE ID : CVE-2025-41048
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/admin.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-41048
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/admin.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41049 - Stored Cross-Site Scripting vulnerability in appRain CMF
CVE ID : CVE-2025-41049
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/appform.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-41049
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/appform.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41050 - Stored Cross-Site Scripting vulnerability in appRain CMF
CVE ID : CVE-2025-41050
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/base_libs.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-41050
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/base_libs.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41051 - Stored Cross-Site Scripting vulnerability in appRain CMF
CVE ID : CVE-2025-41051
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/bootstrap.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-41051
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/bootstrap.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41052 - Stored Cross-Site Scripting vulnerability in appRain CMF
CVE ID : CVE-2025-41052
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/canvasjs.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-41052
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/canvasjs.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41053 - Stored Cross-Site Scripting vulnerability in appRain CMF
CVE ID : CVE-2025-41053
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/commonresource.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-41053
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/commonresource.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41054 - Stored Cross-Site Scripting vulnerability in appRain CMF
CVE ID : CVE-2025-41054
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/cycle.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-41054
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/cycle.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...