High - CVE-2025-7506 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function fromNatlimit of the file /goform/Natlimit of the component HTTP POST Request...
NA - CVE-2025-41442 - A vulnerability exists in Advantech iView...
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an...
NA - CVE-2025-46358 - Emerson ValveLink products
do not use or...
Emerson ValveLink products do not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
NA - CVE-2025-46704 - A vulnerability exists in Advantech iView in...
A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least...
NA - CVE-2025-48496 - Emerson ValveLink products
use a fixed or...
Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
NA - CVE-2025-48891 - A vulnerability exists in Advantech iView that...
A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with...
NA - CVE-2025-52459 - A vulnerability exists in Advantech iView that...
A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges....
NA - CVE-2025-52577 - A vulnerability exists in Advantech iView that...
A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requires an authenticated attacker with at...
NA - CVE-2025-52579 - Emerson ValveLink Products store sensitive...
Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to disk, stored in a core dump, or remain uncleared if the product crashes, or...