Latest CVE Feed
-
5.7
MEDIUMCVE-2022-24926
Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.15-6 allows privileged attackers to trigger a XSS on a victim's devices.... Read more
Affected Products : smarttagplugin- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2024-9539
An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to retrieve metadata information of a user who clicks on the URL and further exploit it to create a convincing phishin... Read more
Affected Products : enterprise_server- Published: Oct. 11, 2024
- Modified: Nov. 15, 2024
-
5.7
MEDIUMCVE-2024-46988
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, users might receive email notification with infor... Read more
Affected Products : tuleap- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
5.7
MEDIUMCVE-2024-51521
Input parameter verification vulnerability in the background service module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Nov. 05, 2024
- Modified: Nov. 07, 2024
-
5.7
MEDIUMCVE-2024-51006
Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the ipv6_static_ip parameter in the ipv6_tunnel function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 22, 2025
-
5.7
MEDIUMCVE-2024-52023
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at pppoe2.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Nov. 05, 2024
- Modified: May. 21, 2025
-
5.7
MEDIUMCVE-2024-52025
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at geniepppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST requ... Read more
- Published: Nov. 05, 2024
- Modified: May. 21, 2025
-
5.7
MEDIUMCVE-2024-8978
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_register_user... Read more
Affected Products : essential_addons_for_elementor- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
5.7
MEDIUMCVE-2024-52711
DI-8100 v16.07.26A1 is vulnerable to Buffer Overflow In the ip_position_asp function via the ip parameter.... Read more
- Published: Nov. 19, 2024
- Modified: Jun. 04, 2025
-
5.7
MEDIUMCVE-2024-49704
A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10.4.1 (All versions), COMOS V10.4.2 (All versions), COMOS V10.4.3 (All versions < V10.4.3.0.47), COMOS V10.4.4 (All versions < V10.4.4.2... Read more
Affected Products :- Published: Dec. 10, 2024
- Modified: Dec. 10, 2024
-
5.7
MEDIUMCVE-2022-31077
KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected versions a malicious message response from KubeEdge can crash the CSI Driver controller server by triggeri... Read more
Affected Products : kubeedge- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2025-46747
An authenticated user without user-management permissions could identify other user accounts.... Read more
Affected Products :- Published: May. 12, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization
-
5.7
MEDIUMCVE-2025-48885
application-urlshortener create shortened URLs for XWiki pages. Versions prior to 1.2.4 are vulnerable to users with view access being able to create arbitrary pages. Any user (even guests) can create these docs, even if they don't exist already. This can... Read more
Affected Products :- Published: May. 30, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authorization
-
5.7
MEDIUMCVE-2023-0023
In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, personal data is shown directly in the URL. They might get captured in log files, bookmarks, and so on disclosing sensitive data of the ... Read more
Affected Products : bank_account_management- Published: Jan. 10, 2023
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2023-21422
Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.... Read more
- Published: Feb. 09, 2023
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2022-47368
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.... Read more
- Published: Feb. 12, 2023
- Modified: Mar. 26, 2025
-
5.7
MEDIUMCVE-2023-26510
Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in which a contributor's draft can only be read by editors until published by an editor. NOTE: the vendor's p... Read more
Affected Products : ghost- Published: Mar. 05, 2023
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2025-48393
The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest version which is availa... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Misconfiguration
-
5.7
MEDIUMCVE-2024-57277
InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Feb. 05, 2025
-
5.7
MEDIUMCVE-2023-2737
Improper log permissions in SafeNet Authentication Service Version 3.4.0 on Windows allows an authenticated attacker to cause a denial of service via local privilege escalation. ... Read more
- Published: Aug. 16, 2023
- Modified: Nov. 21, 2024