A vulnerability has been found in DCN DCME-720 9.1.5.11 and classified as critical. This affects an unknown function of the file /usr/local/www/function/audit/newstatistics/ip_block.php of the component Web Management Backend. Performing manipulation of the argument ip results in os command injection.
This vulnerability is cataloged as CVE-2025-9387. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Other products might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.
Currently trending CVE - Hype Score: 3 - Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device
A vulnerability was found in Oracle Java SE 20.3.13/21.3.9. It has been classified as critical. This vulnerability affects unknown code of the component JavaFX. The manipulation leads to improper authorization.
This vulnerability is uniquely identified as CVE-2024-21005. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability described as critical has been identified in liblnk up to 2018-04-19. Affected is the function liblnk_location_information_read_data of the file liblnk_location_information.c of the component lnk File Handler. The manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2018-12097. The attack can be launched remotely. No exploit exists.
There is ongoing doubt regarding the real existence of this vulnerability.
A vulnerability categorized as critical has been discovered in Oracle VM VirtualBox. The affected element is an unknown function of the component Core. Executing manipulation can lead to an unknown weakness.
This vulnerability appears as CVE-2023-22000. The attack requires local access. There is no available exploit.
A vulnerability labeled as problematic has been found in Oracle VM VirtualBox. This affects an unknown function of the component Core. The manipulation results in information disclosure.
This vulnerability is known as CVE-2023-21988. Attacking locally is a requirement. No exploit is available.
A vulnerability identified as problematic has been detected in aio-libs aiosmtpd up to 1.4.5. The impacted element is an unknown function of the file smtpd.py of the component STARTTLS Handler. The manipulation leads to acceptance of extraneous untrusted data with trusted data.
This vulnerability is referenced as CVE-2024-34083. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
A vulnerability was found in Canonical Apport up to 2.20.x. It has been declared as problematic. This issue affects some unknown processing of the file /var/crash. Such manipulation leads to resource consumption.
This vulnerability is listed as CVE-2022-28653. The attack must be carried out from within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability was found in VMware Spring Framework up to 5.3.31/6.0.16/6.1.3. It has been rated as critical. Affected is the function UriComponentsBuilder of the component URL Parser. Performing manipulation results in server-side request forgery.
This vulnerability was named CVE-2024-22243. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability was found in GStreamer. It has been rated as critical. This affects an unknown part of the component MXF File Parser. The manipulation leads to integer overflow.
This vulnerability is uniquely identified as CVE-2023-40475. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.