Latest CVE Feed
-
5.7
MEDIUMCVE-2023-29680
Cleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attacker on the LAN or WLAN to intercept communications with the router and obtain the password.... Read more
- Published: May. 01, 2023
- Modified: Jan. 30, 2025
-
5.7
MEDIUMCVE-2024-7391
ChargePoint Home Flex Bluetooth Low Energy Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging devices. User interaction i... Read more
- Published: Nov. 22, 2024
- Modified: Dec. 03, 2024
-
5.7
MEDIUMCVE-2024-27106
Vulnerable data in transit in GE HealthCare EchoPAC products... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2024-9469
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and t... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 15, 2024
-
5.7
MEDIUMCVE-2024-51011
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at pppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Nov. 05, 2024
- Modified: May. 21, 2025
-
5.7
MEDIUMCVE-2025-25188
Hickory DNS is a Rust based DNS client, server, and resolver. A vulnerability present starting in version 0.8.0 and prior to versions 0.24.3 and 0.25.0-alpha.5 impacts Hickory DNS users relying on DNSSEC verification in the client library, stub resolver, ... Read more
Affected Products :- Published: Feb. 10, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Cryptography
-
5.7
MEDIUMCVE-2022-43539
A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an attacker in a privileged network position to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information th... Read more
Affected Products : clearpass_policy_manager- Published: Jan. 05, 2023
- Modified: Apr. 10, 2025
-
5.7
MEDIUMCVE-2024-32306
Tenda AC10U v1.0 Firmware v15.03.06.49 has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.... Read more
- Published: Apr. 17, 2024
- Modified: Mar. 17, 2025
-
5.7
MEDIUMCVE-2022-28648
In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered... Read more
Affected Products : youtrack- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2024-51399
Altai Technologies Ltd Altai IX500 Indoor 22 802.11ac Wave 2 AP After login, there are file reads in the background, and attackers can obtain sensitive information such as user credentials, system configuration, and database connection strings, which can ... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 05, 2024
-
5.7
MEDIUMCVE-2024-49501
Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may access the program which is protected by Data Protection function.... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
5.7
MEDIUMCVE-2023-46889
Meross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an unprotected Wi-Fi access point. In this phase, MSH30Q needs to connect to the Internet through a Wi-Fi router. This... Read more
- Published: Jan. 23, 2024
- Modified: Jun. 17, 2025
-
5.7
MEDIUMCVE-2017-13318
In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitati... Read more
Affected Products : android- Published: Jan. 28, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Information Disclosure
-
5.7
MEDIUMCVE-2021-38451
The affected product’s proprietary protocol CSC allows for calling numerous function codes. In order to call those function codes, the user must supply parameters. There is no sanitation on the value of the offset, which allows the client to specify any o... Read more
Affected Products : versiondog- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-31223
SES Evolution before 2.1.0 allows reading some parts of a security policy by leveraging access to a computer having the administration console installed.... Read more
Affected Products : endpoint_security- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2022-28195
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient validation of untrusted data may allow a highly privileged local attacker to cause a integer overflow, which may lead to code execution, e... Read more
- Published: Apr. 27, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2023-1081
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3.... Read more
- Published: Feb. 28, 2023
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2019-0042
Juniper Identity Management Service (JIMS) for Windows versions prior to 1.1.4 may send an incorrect message to associated SRX services gateways. This may allow an attacker with physical access to an existing domain connected Windows system to bypass SRX ... Read more
Affected Products : identity_management_service- Published: Apr. 10, 2019
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2023-21986
Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Native Image). Supported versions that are affected are Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Easily exploitable vulnerability allows un... Read more
Affected Products : graalvm- Published: Apr. 18, 2023
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2010-4110
Unspecified vulnerability in HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform on Integrity servers allows local users to gain privileges or cause a denial of service via unknown vectors.... Read more
- Published: Dec. 22, 2010
- Modified: Apr. 11, 2025