Latest CVE Feed
-
5.7
MEDIUMCVE-2024-57708
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components. NOTE: this is disputed by the Supplier who does not agree it is a prototype pollution vulnerabil... Read more
Affected Products :- Published: Jun. 25, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Denial of Service
-
5.7
MEDIUMCVE-2022-0268
Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28.... Read more
Affected Products : grav- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2022-34574
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing Tftpd32.ini.... Read more
Affected Products : wifi-repeater_firmware- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2023-1149
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.8.0.... Read more
- Published: Mar. 02, 2023
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2020-2677
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Login). Supported versions that are affected are 5.5 and 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via HT... Read more
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2022-46142
Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords.... Read more
Affected Products : scalance_s615_firmware scalance_xm408-4c_firmware scalance_xm408-8c_firmware scalance_xm416-4c_firmware scalance_xr524-8c_firmware scalance_xr526-8c_firmware scalance_xr528-6m_firmware scalance_xr552-12m_firmware scalance_sc632-2c_firmware scalance_sc636-2c_firmware +223 more products- Published: Dec. 13, 2022
- Modified: Jan. 14, 2025
-
5.7
MEDIUMCVE-2024-28956
Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Information Disclosure
-
5.7
MEDIUMCVE-2024-2199
A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.... Read more
- Published: May. 28, 2024
- Modified: Feb. 18, 2025
-
5.7
MEDIUMCVE-2017-5042
Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe a... Read more
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2024-21853
Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors may allow an authorized user to potentially enable denial of service via local access.... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 15, 2024
-
5.7
MEDIUMCVE-2024-41970
A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.... Read more
Affected Products :- Published: Nov. 18, 2024
- Modified: Aug. 27, 2025
-
5.7
MEDIUMCVE-2023-49614
Out of bounds write in firmware for some Intel(R) FPGA products before version 2.9.0 may allow escalation of privilege and information disclosure.... Read more
Affected Products : agilex_7_fpga_firmware- Published: May. 16, 2024
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2016-1156
LINE 4.3.0.724 and earlier on Windows and 4.3.1 and earlier on OS X allows remote authenticated users to cause a denial of service (application crash) via a crafted post that is mishandled when displaying a Timeline.... Read more
- Published: Feb. 19, 2016
- Modified: Apr. 12, 2025
-
5.7
MEDIUMCVE-2024-33875
HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruction pointer.... Read more
Affected Products : hdf5- Published: May. 14, 2024
- Modified: Apr. 18, 2025
-
5.7
MEDIUMCVE-2025-32330
In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept the Auracast audio stream due to an insecure default value. This could lead to remote (proximal/adjacent) information disclosure with no additional execution... Read more
Affected Products : android- Published: Sep. 04, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Information Disclosure
-
5.7
MEDIUMCVE-2024-7347
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built ... Read more
- Published: Aug. 14, 2024
- Modified: Sep. 05, 2025
-
5.7
MEDIUMCVE-2023-6944
A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend,... Read more
- Published: Jan. 04, 2024
- Modified: Sep. 05, 2025
-
5.7
MEDIUMCVE-2024-47820
MarkUs, a web application for the submission and grading of student assignments, is vulnerable to path traversal in versions prior to 2.4.8. Authenticated instructors may download any file on the web server MarkUs is running on, depending on the file perm... Read more
Affected Products : markus- Published: Nov. 18, 2024
- Modified: Sep. 04, 2025
-
5.7
MEDIUMCVE-2024-50996
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the bpa_server parameter at genie_bpa.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a cr... Read more
Affected Products : r7000p_firmware r6400_firmware r6400v2_firmware xr300_firmware r8500_firmware r7000p r8500 xr300 r6400v2- Published: Nov. 05, 2024
- Modified: May. 07, 2025
-
5.7
MEDIUMCVE-2024-52016
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component wlg_adv.cgi via the apmode_dns1_pri and apmode_dns1_sec parameters. These vulnerabilities allo... Read more
Affected Products : r7000p_firmware r6400v2_firmware xr300_firmware r8500_firmware r7000p r8500 xr300 r6400v2- Published: Nov. 05, 2024
- Modified: May. 21, 2025