NA - CVE-2025-29386 - In Tenda AC9 v1.0 V15.03.05.14_multi, the mac...
In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
NA - CVE-2025-29387 - In Tenda AC9 v1.0 V15.03.05.14_multi, the...
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
NA - CVE-2025-29774 - xml-crypto is an XML digital signature and...
xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerability in versions prior to 6.0.1, 3.2.1, and 2.1.6 to bypass authentication...
NA - CVE-2024-12019 - The API used to interact with documents in the...
The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read the contents of files on the underlying operating system. An account with...
NA - CVE-2024-12020 - There is a reflected cross-site scripting (XSS)...
There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthenticated attacker could deceive a user into clicking a crafted link to trigger the...
NA - CVE-2024-12245 - Logout functionality contains a blind SQL...
Logout functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-based blind SQLi technique the attacker can disclose all database contents....
NA - CVE-2024-54445 - Login functionality contains a blind SQL...
Login functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-based blind SQLi technique the attacker can disclose all database contents....
NA - CVE-2024-54446 - Document history functionality contains a blind...
Document history functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a time-based blind SQLi technique the attacker can disclose all database...
NA - CVE-2024-54447 - Saved search functionality contains a blind SQL...
Saved search functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a time-based blind SQLi technique the attacker can disclose all database contents....